logo

Tomiris Unleashes 'Havoc' With New Tools, Tactics

ID: bd33af86-7733-5b00-8d73-00017b6a71cb

STIX ID: report--bd33af86-7733-5b00-8d73-00017b6a71cb

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-12-01

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Kaspersky reports Tomiris, a Russian-speaking APT, conducting an active espionage campaign since early 2025 against diplomatic and government targets across the CIS and Central Asia; the group now uses multi-language implants (Go, Rust, Python, .NET, etc.), routes C2 through legitimate messaging platforms like Telegram and Discord to evade detection, delivers initial access via phishing with password-protected archives, and deploys backdoors and data-harvesting tools to exfiltrate documents and images.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.