Tomiris Hacker Group Added New Tools and Techniques to Attack Organizations Globally
ID: 0e9e8b46-7d44-5abe-99e2-18ba22e8e2a1
STIX ID: report--0e9e8b46-7d44-5abe-99e2-18ba22e8e2a1
Feed Name: cybersecurityNews.com
**Executive summary:** The Tomiris APT has resumed operations with a sophisticated campaign targeting diplomatic and government infrastructure worldwide, using spear-phishing with password-protected archives to deliver multi-language payloads. A notable component is a Rust downloader that inventories sensitive file paths and sends that metadata to Discord webhooks, after which staged payloads are retrieved via VBS/PowerShell loops; the group also leverages Telegram/Discord for C2 and incorporates open-source post-exploitation frameworks to increase stealth and modularity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
