Tomiris
Tomiris is a Russian-speaking cyber-espionage threat actor tracked by Kaspersky since 2021 and linked by Microsoft to a Kazakhstan-based threat actor it tracks as Storm-0473. Reporting in the provided content also states Hydra Saiga likely overlaps with the Tomiris cluster and that both operate for Kazakhstani state interests; other reported overlaps/commonalities include UNC1514, YoroTrooper, ShadowSilk, Silent Lynx, Cavalry Werewolf, SturgeonPhisher, and Comrade Saiga. Tomiris is assessed in the content as distinct from Turla, although some tooling overlaps have been noted, and it has also been linked in reporting to malware such as SUNSHUTTLE (GoldMax), Kazuar, JLORAT, and Telemiris. The group conducts long-term espionage against high-value political, diplomatic, and government targets. Reported targeting includes foreign ministries, intergovernmental organizations, government entities, and diplomats in Russia and across Central Asia/CIS, including Kyrgyzstan, Afghanistan, Turkmenistan, Tajikistan, and Uzbekistan. The content states Tomiris has targeted Russian and Central Asian government officials and diplomats, with more than half of analyzed phishing lures using Russian names/text and other lures localized to national languages for regional targets. Tomiris commonly gains initial access through spear-phishing emails carrying password-protected RAR archives or malicious Word documents/executables disguised as documents, including .doc.exe filename masquerading. The content describes use of phishing emails themed as official government communications, economic development, or partnerships. Tomiris is described as using a broad malware arsenal written in multiple languages including C/C++, C#, Go, Rust, Python, and PowerShell. Reported tooling includes custom reverse shells, backdoors, file grabbers, reverse SOCKS proxies, and open-source post-exploitation frameworks such as Havoc and AdaptixC2. Malware capabilities described in the content include collecting system information, searching for and uploading files, executing remote commands, downloading additional payloads, stopping processes, screen monitoring, and lateral movement/pivoting via proxy tools. One Tomiris backdoor capability explicitly mentioned is uploading files matching hardcoded extensions such as .doc, .docx, .pdf, and .rar. A notable evolution in recent campaigns is Tomiris’s use of legitimate messaging platforms as covert command-and-control and exfiltration channels, especially Telegram and Discord. The content states Tomiris routes C2 traffic through Telegram and Discord, uses Telegram bot-based tools for command execution and data theft, and uses Discord webhooks/channels for exfiltration of system details, file lists, documents, and images. The group is described as persistent and operationally flexible, cycling through disposable malware variants until one evades detection, modifying open-source projects to reduce visibility, and reusing filenames, archive passwords, and infrastructure across campaigns. Persistence via Windows Registry Run keys is also explicitly mentioned. Overall, the provided content characterizes Tomiris as a likely Kazakhstan-aligned espionage actor focused on stealth, persistence, and intelligence collection against government and diplomatic infrastructure in Russia and Central Asia/CIS.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
3 malware families attributed to this actor across reporting.
Observables
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Related/overlapping Kazakhstani state-interest espionage cluster associated with Telegram-based backdoors (e.g., Telemiris) and the Rust backdoor JLORAT; infrastructure and victimology overlap is used in the content to support attribution/relationship to Hydra Saiga.
Actor targeting Russian government/foreign-ministry and intergovernmental orgs; shifting to implants that use public services (e.g., Telegram/Discord) for stealthier C2.
Tomiris is conducting cyber-espionage campaigns and has recently evolved its tactics and tools in a new wave of attacks.
Tomiris is conducting espionage campaigns targeting diplomatic entities, using a polyglot strategy and hijacking Telegram and Discord as covert command and control (C2) channels.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.