Threat Intelligence, Malware, Phishing

Tomiris bolsters attack playbook sophistication

Internet security and personal data theft concept with blue shadows faceless hackers in hoody using laptop and abstract virtual technological symbols

Threat operation Tomiris has harnessed more sophisticated techniques to stealthily compromise Russian and Central Asian government officials and diplomats since early this year, according to GBHackers News.

Tomiris has used phishing emails purporting to be government communications on economic development or partnerships to spread a password-protected archive containing a Microsoft Word-spoofing file that infects targeted devices, a report from Kaspersky revealed. Clandestine operations are then ensured by a Rust-based tool that delivers system details and file lists to a private Discord channel and other Telegram bot-exploiting tools that obtain commands and deliver stolen information.

More valuable targets have also been downloaded with the AdaptixC2 and Havoc open-source frameworks to enable sensitive data theft, screen activity monitoring, and further government network compromise.

Tomiris's renewed focus on long-term espionage should prompt intensified tracking of network traffic, including in Telegram and other trusted apps, Kaspersky researchers said.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds