Tomiris APT Shifts to Telegram, Discord for Stealthy Cyberattacks

  • The threat actor Tomiris targets government and intergovernmental organizations in Russia and Central Asia.
  • New tactics involve using public services like Telegram and Discord for command-and-control to evade detection.
  • Spear-phishing campaigns use region-specific languages and Russian-themed content, focusing on Russian-speaking targets and Central Asian countries.
  • Multiple Malware families and custom implants are deployed, utilizing various programming languages and open-source frameworks.
  • The group shows operational flexibility with multi-language malware to maintain stealth and long-term persistence.

Tomiris, a threat actor active since at least 2021, has been conducting cyberattacks targeting foreign ministries, government entities, and intergovernmental organizations in Russia and Central Asia. These campaigns aim to gain remote access and deliver additional malicious tools, focusing heavily on intelligence gathering. Attacks have been especially prevalent in Russia, Turkmenistan, Kyrgyzstan, Tajikistan, and Uzbekistan.

- Advertisement -

The group’s recent activity reveals a shift in tactics that includes the use of implants leveraging public platforms like Telegram and Discord for command-and-control (C2) communication. This technique likely helps blend malicious traffic with legitimate service activity, reducing detection risks, as noted by researchers Oleg Kupreev and Artem Ushkov in their analysis.

Spear-phishing emails are crafted carefully with Russian names and text in over half the cases, emphasizing Russian-speaking targets. Other campaigns employ native languages of Central Asian countries. These emails often contain password-protected RAR archives with executables disguised as documents. Once executed, the malware installs reverse shells and backdoors, establishes persistence through Windows Registry modifications, and connects to servers running open-source frameworks such as Havoc and AdaptixC2.

Additional malware delivered via these emails includes a Rust-based downloader that communicates with Discord webhooks, a Python reverse shell using Discord for C2, and a backdoor called Distopia based on the open-source dystopia-c2 project. Distopia uses Discord and Telegram for executing commands and exfiltrating data.

Tomiris also deploys various reverse shells and implants developed in languages like C#, Rust, Go, and PowerShell. These tools utilize Telegram for command reception and operate with multiple communication protocols and techniques. Some employ modified versions of open-source reverse SOCKS proxies written in C++ and Go to hide activity.

- Advertisement -

“The Tomiris 2025 campaign leverages multi-language malware modules to enhance operational flexibility and evade detection by appearing less suspicious,” stated the Cybersecurity company. The evolution in tactics emphasizes stealth, persistence, and targeted attacks on political and diplomatic infrastructures.

Earlier studies associate Tomiris with malware families linked to known Russian APT groups but regard it as a distinct actor primarily focused on Central Asia. Microsoft’s December 2024 report connected the backdoor with a Kazakhstan-based group called Storm-0473, while other analyses noted overlaps with several other clusters such as Cavalry Werewolf, ShadowSilk, and Silent Lynx.

Cyberattacks Illustration

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Ethereum Leads Bitcoin Liquidations as Macro Headwinds Bite.

Ethereum led crypto liquidations over the last 24 hours, surpassing Bitcoin.Total crypto liquidations totaled...

Bitcoin Falls Amid US-EU Tariff Fears, Drops Near $92K today

Bitcoin traded near $92,000 on Jan. 19 after a weekend decline tied to concerns...

UK committee: regulators lag as AI reshapes financial sector

The UK’s Treasury Committee warns AI use in finance is outpacing regulatory oversight.Regulators are...

Bitcoin Holds at $92K Amid Trade Tensions, Volatility Fears.

Bitcoin stabilized near $92,000 after a liquidation-driven sell-off on Monday.Options markets show rising demand...

Trove Keeps $9.4M for Solana Pivot; Investors Demand Refunds

Trove Markets will keep about $9.4 million of an over $11.5 million raise and...
- Advertisement -

Must Read

9 Best Trading Platforms for Crypto Beginners

Many newcomers to the crypto space are looking for platforms to buy, sell and exchange cryptocurrencies. While there are hundreds of crypto exchanges around...
Bitcoin (BTC) $ 90,887.00 1.78%
Ethereum (ETH) $ 3,116.85 2.35%
XRP (XRP) $ 1.95 0.29%
Bittensor (TAO) $ 244.71 0.86%
Polkadot (DOT) $ 1.99 1.52%
Cardano (ADA) $ 0.366375 1.41%
Chainlink (LINK) $ 12.64 0.74%
Hyperliquid (HYPE) $ 23.27 2.17%
Monero (XMR) $ 594.83 4.58%
Hedera (HBAR) $ 0.109129 0.12%
Toncoin (TON) $ 1.57 1.83%