logo

Tomiris wreaks Havoc: New tools and techniques of the APT group

ID: 98f71f21-7db6-5c97-bf30-b7fc09aa4c09

STIX ID: report--98f71f21-7db6-5c97-bf30-b7fc09aa4c09

Feed Name: Securelist by Kaspersky

Threat Score
90/100

Date Published: 2025-11-28

Date Updated: 2026-04-29

Author: Oleg Kupreev, Artem Ushkov

...
...

Kaspersky reports that the Tomiris APT launched a 2025 campaign targeting foreign ministries, intergovernmental organizations, and government entities using multi-language implants (Go, Rust, C/C#/C++, Python, PowerShell), leveraging public services (Telegram/Discord) for C2 and deploying post-exploitation frameworks (AdaptixC2, Havoc); the report includes detailed technical analysis, attack chains, and extensive IOCs (file hashes, domains, IPs, URLs, webhooks) for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.