logo

Tomiris Hacker Group Added New Tools and Techniques to Attack Organizations Globally

ID: 0e9e8b46-7d44-5abe-99e2-18ba22e8e2a1

STIX ID: report--0e9e8b46-7d44-5abe-99e2-18ba22e8e2a1

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-01

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Executive summary:** The Tomiris APT has resumed operations with a sophisticated campaign targeting diplomatic and government infrastructure worldwide, using spear-phishing with password-protected archives to deliver multi-language payloads. A notable component is a Rust downloader that inventories sensitive file paths and sends that metadata to Discord webhooks, after which staged payloads are retrieved via VBS/PowerShell loops; the group also leverages Telegram/Discord for C2 and incorporates open-source post-exploitation frameworks to increase stealth and modularity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.