Tomiris Unleashes 'Havoc' With New Tools, Tactics
ID: bd33af86-7733-5b00-8d73-00017b6a71cb
STIX ID: report--bd33af86-7733-5b00-8d73-00017b6a71cb
Feed Name: Dark Reading
Kaspersky reports Tomiris, a Russian-speaking APT, conducting an active espionage campaign since early 2025 against diplomatic and government targets across the CIS and Central Asia; the group now uses multi-language implants (Go, Rust, Python, .NET, etc.), routes C2 through legitimate messaging platforms like Telegram and Discord to evade detection, delivers initial access via phishing with password-protected archives, and deploys backdoors and data-harvesting tools to exfiltrate documents and images.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
