ZeroHour
Recorded Futurepublished ()ingested Insikt Group®

Multi-Layered TDS Infrastructure Linked to Major Cyber Threats

highRansomwareimportance 57

Indicators of compromiseAll →

TypeIndicatorContext
domaincheck-googlle.com[.]com), while others appear to impersonate Google (such as check-googlle[.]com ) (see Table 3 ). This suggests that the website may func
domaindownloading.bplnetempresas.comclicks the “Update Chrome” button, the website redirects to downloading[.]bplnetempresas[.]com , which shows the IP address 146.70.41[.]191 combined w
domainmktgads.comoted in the Compromised WordPress Websites section (such as mktgads[.]com), while others appear to impersonate Google (such as chec
domainpemalite.comosted on 45[.]61[.]136[.]67 , namely piedsmontlaw[.]com and pemalite[.]com , were already resolving to this IP address in 2022, indi
domainpiedsmontlaw.comOf note, two domains hosted on 45[.]61[.]136[.]67 , namely piedsmontlaw[.]com and pemalite[.]com , were already resolving to this IP ad
domainupdate-chronne.comtypographical error observed in earlier reports. The domain update-chronne[.]com, hosted behind Cloudflare, appears to be owned by the thr
domainwl.gle 6 ). The URL was redirected via the shortened URL https://wl[.]gl/25dW64 . Figure 6 : PowerShell script hosted on https://u
domainwww.ecowas.intromised websites. For instance, the website associated with www[.]ecowas[.]int has consistently changed the URL used to fetch the Java
domainwww.pcbc.gov.pllinked to the Polish Centre for Testing and Certification, www[.]pcbc[.]gov[.]pl , and the domain of the Economic Community of West Af
Full article1,672 words · extracted from recordedfuture.com · click to collapse

Analysis cut-off date: January 7, 2025

NOTE: This report was updated on May 12, 2025, after it was discovered that TAG-124 is unrelated to 404TDS. All references to 404TDS as an alias belonging to TAG-124 have been removed.

Executive Summary

Insikt Group has identified multi-layered infrastructure linked to a traffic distribution system (TDS) tracked by Recorded Future as TAG-124, which overlaps with threat activity clusters known as LandUpdate808, KongTuke, and Chaya_002. TAG-124 comprises a network of compromised WordPress sites, actor-controlled payload servers, a central server, a suspected management server, an additional panel, and other components. The threat actors behind TAG-124 demonstrate high levels of activity, including regularly updating URLs embedded in the compromised WordPress sites, adding servers, refining TDS logic to evade detection, and adapting infection tactics, as demonstrated by their recent implementation of the ClickFix technique.

Insikt Group identified multiple threat actors using TAG-124 within their initial infection chains, including operators of Rhysida ransomware, Interlock ransomware, TA866/Asylum Ambuscade, SocGholish, D3F@CK Loader, TA582, and others. Notably, the shared use of TAG-124 reinforces the connection between Rhysida and Interlock ransomware, which are already linked through similarities in tactics, tools, encryption behaviors, ransom note themes, code overlaps, and data exfiltration techniques. Insikt Group expects that TAG-124 will continue its operations within the increasingly sophisticated and specialized cybercriminal ecosystem, enhance its effectiveness, and attract additional users and partners.

Key Findings

  • Insikt Group identified multi-layered infrastructure linked to a TDS tracked as TAG-124. This infrastructure includes a network of compromised WordPress sites, likely actor-controlled payload servers, a central server, a suspected management server, and an additional panel, among other components.
  • The threat actor(s) associated with TAG-124 appear highly active, regularly updating URLs on compromised WordPress sites to evade detection, adding new servers to their infrastructure, and improving TDS-linked conditional logic and infection tactics.
  • Multiple threat actors are assessed to incorporate TAG-124’s service into their initial infection chains, including operators of Rhysida ransomware, Interlock ransomware, TA866/Asylum Ambuscade, SocGholish, D3F@CK Loader, TA582, and others.
  • While Rhysida and Interlock ransomware have been associated with each other due to similarities in tactics, tools, encryption behaviors, ransom note themes, overlaps in code, and data exfiltration techniques, the shared use of TAG-124 reinforces this connection.

Background

TAG-124, which overlaps with LandUpdate808, KongTuke, and Chaya_002, is a TDS used to distribute malware on behalf of various threat actors, including operators of Rhysida ransomware, Interlock ransomware, TA866/Asylum Ambuscade, SocGholish, D3F@CK Loader, and TA582, among others (1, 2, 3). A TDS typically refers to a system used to analyze and redirect web traffic based on parameters like geolocation or device type, funneling only specific visitors to malicious destinations such as phishing sites, malware, or exploit kits, while evading detection and optimizing cybercriminal campaigns.

More specifically, TAG-124 operates by injecting malicious JavaScript code into compromised WordPress websites. When visitors access an infected website, they unknowingly load attacker-controlled resources designed to manipulate them into completing actions that result in the download and execution of malware. TAG-124 often deceives victims by presenting the malware as a required Google Chrome browser update.

In more recent variations, TAG-124 has been observed using the ClickFix technique. This approach displays a dialog instructing visitors to execute a command pre-copied to their clipboard. Once a visitor runs the command, it initiates a multi-stage process that downloads and executes the malware payload.

Threat Analysis

TAG-124

Insikt Group identified multi-layered infrastructure associated with the TDS TAG-124. This infrastructure comprises a network of compromised WordPress sites, likely actor-controlled payload servers, a central server whose exact purpose remains unclear at the time of analysis, a suspected management server, and an additional management panel. If visitors fulfill specific criteria, the compromised WordPress websites display fake Google Chrome update landing pages, which ultimately lead to malware infections as discussed in the Users of TAG-124 section of this report (see Figure 1).

Figure 1: TAG-124’s high-level infrastructure setup (Source: Recorded Future)

Compromised WordPress Websites

TAG-124’s infrastructure consists of an extensive network of WordPress websites (see Appendix A). These websites appear to lack a consistent theme regarding industry, topic, or geography, suggesting they were likely compromised opportunistically through exploits or by acquiring credentials, such as those obtained via infostealers.

First-Stage WordPress Websites in Initial Delivery

The compromised websites of the first stage in the initial delivery phase typically include a script tag with an async attribute at an arbitrary location in the document object model (DOM), enabling the loading of an external JavaScript file in parallel with the page to avoid rendering delays (see Figure 2).

Figure 2: Script tag in DOM used to load external JavaScript file (Source: URLScan)

The JavaScript filename has changed frequently over time, with earlier names following recognizable patterns (such as metrics.js) and more recent ones appearing to be randomly formatted (such as hpms1989.js). Example filenames include:

  • 3561.js
  • 365h.js
  • e365r.js
  • hpms1989.js
  • metrics.js
  • nazvanie.js
  • web-analyzer.js
  • web-metrics.js
  • web.js
  • wp-config.js
  • wp.js

Notably, the threat actors appear to be regularly updating the URLs on the compromised websites. For instance, the website associated with www[.]ecowas[.]int has consistently changed the URL used to fetch the JavaScript file. This behavior indicates that the threat actors maintain ongoing access to these WordPress sites and frequently alter the URLs, including the domain and JavaScript filename, likely to evade detection.

Although many of the compromised WordPress websites appear to be associated with lesser-known organizations, Insikt Group identified notable cases, including a subdomain linked to the Polish Centre for Testing and Certification, www[.]pcbc[.]gov[.]pl, and the domain of the Economic Community of West African States (ECOWAS) (www[.]ecowas[.]int). Both have been compromised and used in TAG-124 campaigns.

Final Stage WordPress Websites in Initial Delivery

If visitors meet specific criteria, which could not be fully determined, the compromised WordPress domains typically present fake Google Chrome update landing pages. These pages prompt users to click a download button, triggering the download of the actual payload from designated endpoints on a secondary set of compromised WordPress websites, including but likely not limited to:

  • /wp-admin/images/wfgth.php
  • /wp-includes/pomo/update.php
  • /wp-content/upgrade/update.php
  • /wp-admin/images/rsggj.php
Fake Google Chrome Update Landing Pages

Insikt Group discovered two variants of fake Google Chrome update landing pages associated with TAG-124 (see Figure 3). According to URLScan submission data, Variant 1 has been active longer, with its earliest submission recorded on April 24, 2024.

Figure 3: Fake Google Chrome update variant 1 (left) and 2 (right) (Source: URLScan, URLScan)

Only victims meeting a specific set of still unknown conditions are directed to the fake Google Chrome update landing page, resulting in the observation of only a limited number of domains (see Table 1). These domains can be attributed to TAG-124 based on the URLs embedded in the DOM, public reporting, or other indicators. Notably, the threat actors consistently misspell the word “referer” as “refferer” in the query parameter, a typographical error observed in earlier reports.

The domain update-chronne[.]com, hosted behind Cloudflare, appears to be owned by the threat actors as it directly impersonates Google Chrome (see Figure 4). At the time of analysis, the domain was still active, indexed by Google Search, and hosted the file Release.zip, which was identified as REMCOS RAT.

Google Chrome fake update landing page Figure 4: Google Chrome fake update landing page on update-chronne[.]com (Source: Recorded Future)

Notably, when a victim clicks the “Update Chrome” button, the website redirects to downloading[.]bplnetempresas[.]com, which shows the IP address 146.70.41[.]191 combined with three different ports (see Figure 5). This IP address has previously been associated with REMCOS RAT.

Figure 5: Suspected REMCOS RAT command-and-control (C2) server shown on downloading[.]bplnetempresas[.]com (Source: Recorded Future)

Additionally, the domain hosted a file named moc.txt, containing a PowerShell script designed to download and execute the contents of Release.zip (see Figure 6). The URL was redirected via the shortened URL https://wl[.]gl/25dW64.

PowerShell script Figure 6: PowerShell script hosted on https://update-chronne[.]com/moc.txt as of September 12, 2024 (Source: URLScan)

Suspected Shell Website

Both update-chronne[.]com and downloading[.]bplnetempresas[.]com hosted a website seemingly associated with "YSOFEL", which appears to be a Brazilian organization (see Figure 7). However, no information about this organization could be found online, indicating that it is likely a fictitious entity.

Figure 7: Suspected shell website linked to a fake Brazilian organization (Source: URLScan)

Insikt Group identified several other domains, some of which are noted in the Compromised WordPress Websites section (such as mktgads[.]com), while others appear to impersonate Google (such as check-googlle[.]com) (see Table 3). This suggests that the website may function as a "shell website", potentially used to age domains or to display content only when visitors meet specific criteria.

Most of the domains began resolving in November 2024, suggesting that TAG-124 gained momentum during this period, with the majority of the domains still active at the time of analysis. Of note, two domains hosted on 45[.]61[.]136[.]67, namely piedsmontlaw[.]com and pemalite[.]com, were already resolving to this IP address in 2022, indicating that the server may have already been under the control of the threat actor during that time.

Suspected Higher-Tier Infrastructure

The majority of the suspected threat actor-controlled TAG-124 delivery servers, as listed in the TAG-124 Delivery Servers section, have been seen communicating with a server over TCP port 443 (see Figure 1). The configurations of this server are similar to those of the delivery servers and host a domain that returns only a generic HTML page when accessed. At the time of analysis, Insikt Group could not determine the exact purpose of this server but suspects it plays a central role in the operation. One possibility is that it contains the core logic of the TDS.

Additionally, Insikt Group identified a suspected management server linked to TAG-124. This server has been observed communicating with the delivery servers via TCP ports 80 and 443. It has also interacted with another panel linked to TAG-124, referred to as the "Ads Panel", whose purpose includes serving the latest delivery server through a specified endpoint, among others (see Figure 1).

TAG-124’s Multi-Layered TDS Infrastructure and Extensive User Base

Read the Complete Analysis

Download report

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base