Skip to content
skopnix
← adversaries
Unknown · assessed origin China

TAG-28

misp-galaxyrefreshed 2026-09-15

sigil

Analyst brief

TAG-28 is a Chinese state-sponsored threat actor that has been targeting Indian organizations, including media conglomerates and government agencies. They have been using the Winnti malware, which is commonly shared among Chinese state-sponsored groups. TAG-28's main objective is to gather intelligence on Indian targets, potentially for espionage purposes.

Take it with you
References
Early access

Track TAG-28 on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected