Home/Threat Actor/TAG-100
Threat Actor

TAG-100

tag_100 · china · active since 2022-01

TAG-100 (Recorded Future Insikt Group canonical designation, July 16, 2024 first-disclosure) is a China-aligned cyber espionage cluster targeting governments and private sector organizations globally with documented victims across Africa (including Djibouti government), Asia (including Cambodian government), North America, South America (including Dominican Republic government), and Oceania; intergovernmental organizations and foreign ministries represent significant targeting concentration consistent with Chinese state diplomatic intelligence collection priorities.

signature operational tradecraft is (1) systematic exploitation of perimeter-network appliance N-day vulnerabilities including Citrix NetScaler (CVE-2023-3519, CVE-2023-4966), F5 BIG-IP (CVE-2023-46747), Ivanti Connect Secure (CVE-2023-46805 + CVE-2024-21887 chain), Cisco IOS XE (CVE-2023-20198), and Palo Alto PAN-OS (CVE-2024-3400); and (2) extensive use of open-source RAT tooling, Pantegana (Go-based multi-platform RAT) and Spark RAT, operationally distinct from custom-RAT-developing APT* China-aligned clusters (PlugX, ShadowPad, Korplug)

operationally distinct from Volt Typhoon, Salt Typhoon, Silk Typhoon, Flax Typhoon, Storm-0558, Earth Estries, and APT* clusters all curated separately in this corpus.

china confidence: high 7 aliases

Profile

TAG-100 (Recorded Future Insikt Group canonical designation, July 16, 2024 first-disclosure) is a China-aligned cyber espionage cluster assessed with high confidence as a Chinese state-aligned advanced persistent threat actor conducting cyber espionage operations against governments and selected private sector organizations globally. The cluster's victimology spans approximately 16 documented victim organizations across Africa, Asia, North America, South America, and Oceania, including Cambodian, Djibouti, and Dominican Republic governmental organizations, intergovernmental organizations, multiple foreign ministries, technology firms, financial services organizations, and consulting firms. The cluster's operational distinctiveness is concentrated in two dimensions: (1) PERIMETER-NETWORK APPLIANCE N-DAY EXPLOITATION SIGNATURE.

TAG-100's signature initial-access tradecraft is systematic exploitation of perimeter-network appliance N-day vulnerabilities, including Citrix NetScaler ADC (CVE-2023-3519 RCE, CVE-2023-4966 NetScaler bleed), F5 BIG-IP (CVE-2023-46747), Ivanti EPM and Ivanti Connect Secure (CVE-2023-46805 and CVE-2024-21887 chain), Cisco IOS XE (CVE-2023-20198), and Palo Alto Networks PAN-OS. The perimeter-appliance N-day exploitation tradecraft provides high-value network-perimeter footholds for subsequent lateral movement and is operationally consistent with broader Chinese-aligned cyber-operations tradecraft of leveraging N-day perimeter-device exploitation rather than zero-day acquisition. (2) OPEN-SOURCE RAT TOOLING OPERATIONAL PATTERN.

TAG-100's signature command-and-control tradecraft is extensive use of open-source RAT tooling, Pantegana (Go-based multi- platform RAT) and Spark RAT (open-source RAT framework with Chinese-language documentation). The open-source-RAT tradecraft operationally distinguishes TAG-100 from clusters that develop custom RAT tooling (the APT* China-aligned clusters generally develop custom RAT families including PlugX, ShadowPad, Korplug) and operationally positions TAG-100 within a sub-pattern of Chinese-aligned clusters that leverage open-source tooling for operationally-resourced but tooling-frugal operations. The open-source-RAT pattern provides operational advantages including reduced custom- tooling-development overhead, attribution ambiguity advantages, and operational flexibility from active open- source community tooling maintenance.

The cluster's targeting profile concentration on intergovernmental organizations and foreign ministries is consistent with Chinese state intelligence priorities on diplomatic intelligence collection, operationally similar in target- profile-significance to Storm-0558 (storm_0558.yaml, US State Department Exchange Online token-forging intrusion) and operationally distinct from the critical-infrastructure- preposition targeting of Volt Typhoon (volt_typhoon.yaml), the telecommunications-targeting of Salt Typhoon (salt_typhoon.yaml) and Earth Estries (earth_estries.yaml), and the broader-mandate APT* China-aligned clusters. TAG-100 is operationally distinct from all other Chinese- aligned clusters curated separately in this corpus and fills the open-source-RAT-tooling / perimeter-appliance-N-day- exploitation cell in the curated Chinese-cluster coverage.

Aliases

7
tag_100tag-100tag 100threat activity group 100china-aligned-tag-100-clusterivanti-cisco-citrix-exploitation-cluster-2024tag100

Notable Campaigns

3
2024Recorded Future Insikt Group Canonical Public Disclosure, TAG-100 (July 2024)
2022-2024Perimeter-Network Appliance N-Day Exploitation Operational Signature
2022-2024Open-Source RAT Tooling Operational Pattern, Pantegana and Spark RAT

Attribution & Reporting

Attributed by
Recorded Future Insikt GroupMandiant (Google Threat Intelligence)CrowdStrikeSentinelOneMicrosoft Threat IntelligenceSymantec / Broadcom Threat Hunter TeamCisco TalosCISA (US Cybersecurity and Infrastructure Security Agency)UK National Cyber Security Centre (NCSC)Canadian Centre for Cyber Security (CCCS)Trend Micro
Key reporting
reportRecorded Future Insikt Group: TAG-100 Uses Open-Source Tools, Targets Intergovernmental Organizations (July 16, 2024), canonical first-disclosure
reportMandiant / Google Threat Intelligence: TAG-100 China Perimeter Exploitation Analysis
reportCrowdStrike: TAG-100 China-Aligned Cluster Operational Analysis
reportCISA Cybersecurity Advisory: TAG-100 / China Perimeter Appliance Exploitation Indicators
reportMalpedia Actor Profile: TAG-100

Operational

State sponsor

China-aligned cyber espionage cluster assessed by Recorded Future Insikt Group (canonical TAG-100 designation, July 2024 disclosure) with high confidence to be a Chinese state-aligned advanced persistent threat actor conducting cyber espionage operations against governments and selected private sector organizations globally. Recorded Future's attribution is based on the cluster's operational tradecraft (long-dwell espionage operations against high-value governmental and intergovernmental targets), targeting profile (intergovernmental organizations, foreign ministries, governmental research institutions, technology firms, financial services, consulting firms, consistent with Chinese state intelligence priorities), exploitation of perimeter-network appliance vulnerabilities (Citrix NetScaler, F5 BIG-IP, Ivanti EPM and adjacent products, Cisco IOS XE, Palo Alto Networks PAN-OS, operationally consistent with broader Chinese-aligned cyber-operations tradecraft of leveraging perimeter-device N-day exploitation for initial access), infrastructure analysis correlating with broader Chinese-aligned operational patterns, and use of open-source remote access tooling (Pantegana, Spark RAT) operationally consistent with Chinese-aligned tooling adoption patterns. The cluster has not been formally attributed by any government cybersecurity authority to a specific Chinese government agency, military unit (PLA SSF), or intelligence service (MSS).

The cluster is operationally distinct from the broader Chinese-aligned cluster ecosystem curated in this corpus including Volt Typhoon (volt_typhoon.yaml), Salt Typhoon (salt_typhoon.yaml), Silk Typhoon (silk_typhoon.yaml), Flax Typhoon (flax_typhoon.yaml), Storm-0558 (storm_0558.yaml), Earth Estries (earth_estries.yaml), GhostEmperor (ghostemperor.yaml), and the APT* China-aligned clusters (APT1, APT3, APT10, APT17, APT31, APT40, APT41) , though all operate within the broader Chinese state- aligned cyber-operations ecosystem.

Motivations
cyber_espionage, intergovernmental_organization_intelligence_collection, government_diplomatic_intelligence_collection, foreign_policy_intelligence, chinese_state_intelligence_priorities, long_dwell_persistent_access_operations
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)34/60 · 56%
Runtime / container (Falco)12/60 · 20%
File / malware (YARA)1/60 · 1%
Network (Suricata/Snort)17/60 · 28%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
METASPLOITSPARK RAT
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin