TAG-56 is an Iran-nexus cyber espionage group known for credential harvesting via fake pages and spearphishing.
Analyst brief
TAG-56 is assessed as an Iran-nexus cyber espionage group with TTP overlaps with APT42. They primarily target individuals through credential harvesting campaigns using fake registration pages and spearphishing, often luring victims to encrypted chat platforms like WhatsApp or Telegram. Their key TTPs include the use of purpose-built infrastructure, such as shared web hosts and recycled code, rather than developing custom tools. Defenders should focus on detecting suspicious login portals, blocking phishing attempts originating from mobile messaging apps, and enforcing MFA to prevent credential reuse attacks.
TAG-56
unknown
TAG-56 is a threat actor group that shares similarities with the APT42 group. They use tactics such as fake registration pages and spearphishing to target victims, often using encrypted chat platforms like WhatsApp or Telegram. TAG-56 is believed to be part of a broader campaign led by an Iran-nexus threat activity group. They have been observed using shared web hosts and recycled code, indicating a preference for acquiring purpose-built infrastructure rather than establishing their own.
What are the main techniques used by TAG-56 to harvest credentials?+
TAG-56 primarily targets individuals through credential harvesting campaigns using fake registration pages and spearphishing, often luring victims to encrypted chat platforms like WhatsApp or Telegram.
What approach does TAG-56 prefer for building its infrastructure?+
TAG-56 prefers acquiring purpose-built infrastructure rather than establishing their own, including the use of shared web hosts and recycled code.