Threat operation Tomiris has harnessed more sophisticated techniques to stealthily compromise Russian and Central Asian government officials and diplomats since early this year, according to GBHackers News.
Tomiris has used phishing emails purporting to be government communications on economic development or partnerships to spread a password-protected archive containing a Microsoft Word-spoofing file that infects targeted devices, a report from Kaspersky revealed. Clandestine operations are then ensured by a Rust-based tool that delivers system details and file lists to a private Discord channel and other Telegram bot-exploiting tools that obtain commands and deliver stolen information.
More valuable targets have also been downloaded with the AdaptixC2 and Havoc open-source frameworks to enable sensitive data theft, screen activity monitoring, and further government network compromise.
Tomiris's renewed focus on long-term espionage should prompt intensified tracking of network traffic, including in Telegram and other trusted apps, Kaspersky researchers said.
Tomiris has used phishing emails purporting to be government communications on economic development or partnerships to spread a password-protected archive containing a Microsoft Word-spoofing file that infects targeted devices, a report from Kaspersky revealed. Clandestine operations are then ensured by a Rust-based tool that delivers system details and file lists to a private Discord channel and other Telegram bot-exploiting tools that obtain commands and deliver stolen information.
More valuable targets have also been downloaded with the AdaptixC2 and Havoc open-source frameworks to enable sensitive data theft, screen activity monitoring, and further government network compromise.
Tomiris's renewed focus on long-term espionage should prompt intensified tracking of network traffic, including in Telegram and other trusted apps, Kaspersky researchers said.
