Tomiris is a cyber-espionage threat actor tracked by Kaspersky since 2021. The group is described as Russian-speaking and has been attributed to campaigns targeting foreign ministries, intergovernmental organizations, government entities, and diplomatic targets in Russia, Central Asia, and other CIS countries, including Turkmenistan, Kyrgyzstan, Tajikistan, and Uzbekistan. Reported objectives include establishing remote access, stealing internal documents, and maintaining long-term persistence against high-value political and diplomatic infrastructure. Recent operations beginning in early 2025 used spear-phishing emails with malicious password-protected RAR archives, often containing executables disguised as Word documents. More than half of observed lures reportedly used Russian names and text, while other lures were localized for Central Asian targets. Tomiris has used custom and modified malware written in C/C++, C#, Go, Rust, Python, and PowerShell, alongside open-source post-exploitation frameworks including Havoc and AdaptixC2. Reported capabilities include remote command execution, file upload and download, process stopping, system reconnaissance, document collection, reverse shells, file grabbers, and reverse SOCKS proxying. Persistence via Windows Registry Run keys is also described. A notable feature of Tomiris activity is the use of legitimate platforms such as Telegram and Discord for command-and-control and data exfiltration. Reported tooling includes Rust- and Python-based implants that collect system information and files, compress data, and upload it to C2 or Discord servers, as well as Telegram-based reverse shells and bot-driven control. The group is described as persistent and operationally flexible, cycling through disposable malware variants until one evades detection. The content notes overlaps or possible relationships between Tomiris and several other tracked clusters. Microsoft attributed the Tomiris backdoor to a Kazakhstan-based threat actor tracked as Storm-0473. Other reporting cited in the content links or overlaps Tomiris with UNC1514, Hydra Saiga, YoroTrooper, ShadowSilk, Silent Lynx, SturgeonPhisher, Cavalry Werewolf, and Comrade Saiga. The content also states Hydra Saiga likely overlaps with the Tomiris threat cluster and may operate for Kazakhstani state interests. Tomiris has also been reported to share some tooling overlap with Turla, SUNSHUTTLE (GoldMax), and Kazuar, while being assessed as a distinct threat actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Related/overlapping Kazakhstani state-interest espionage cluster associated with Telegram-based backdoors (e.g., Telemiris) and the Rust backdoor JLORAT; infrastructure and victimology overlap is used in the content to support attribution/relationship to Hydra Saiga.
Actor targeting Russian government/foreign-ministry and intergovernmental orgs; shifting to implants that use public services (e.g., Telegram/Discord) for stealthier C2.
Tomiris is conducting cyber-espionage campaigns and has recently evolved its tactics and tools in a new wave of attacks.
Tomiris is conducting espionage campaigns targeting diplomatic entities, using a polyglot strategy and hijacking Telegram and Discord as covert command and control (C2) channels.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.