TAG-22

Threat Actor updated 23 days ago (2024-11-29T14:28:28.496Z)
Download STIX
Preview STIX
Threat Activity Group 22 (TAG-22), also known as RedHotel, is a suspected Chinese state-sponsored threat actor that has been identified by Recorded Future. This group has been actively targeting various sectors including telecommunications, academia, research and development, and government organizations across several countries including Nepal, the Philippines, Taiwan, and historically, Hong Kong. TAG-22 is recognized for its persistence, prominence, operational intensity, and global reach, posing a significant cybersecurity threat. Insikt Group has been closely tracking the activities of TAG-22 and has noted some historical overlap with other threat groups such as APT41 and Barium. These groups have been previously clustered by FireEye and Microsoft respectively. The overlapping activities suggest possible collaborations or shared tactics, techniques, and procedures (TTPs) among these threat actors, which further complicates the cybersecurity landscape. TAG-22's activities underscore the evolving and complex nature of state-sponsored cyber threats. Their ability to persistently target and infiltrate high-value sectors around the globe highlights the necessity for robust cybersecurity measures and international cooperation. Organizations in the targeted sectors need to be particularly vigilant and proactive in their defense strategies to mitigate the risk posed by this and similar threat actors.
Description last updated: 2023-11-29T06:37:48.901Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the TAG-22 Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more