Tomiris wreaks Havoc: New tools and techniques of the APT group
ID: 98f71f21-7db6-5c97-bf30-b7fc09aa4c09
STIX ID: report--98f71f21-7db6-5c97-bf30-b7fc09aa4c09
Feed Name: Securelist by Kaspersky
Kaspersky reports that the Tomiris APT launched a 2025 campaign targeting foreign ministries, intergovernmental organizations, and government entities using multi-language implants (Go, Rust, C/C#/C++, Python, PowerShell), leveraging public services (Telegram/Discord) for C2 and deploying post-exploitation frameworks (AdaptixC2, Havoc); the report includes detailed technical analysis, attack chains, and extensive IOCs (file hashes, domains, IPs, URLs, webhooks) for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
