Tomiris is a backdoor/malware family associated in reporting with the Tomiris threat cluster. It was first publicly detailed by Kaspersky in September 2021. The malware has been noted to share links with SUNSHUTTLE (GoldMax), used by APT29 in the SolarWinds intrusion, and Kazuar, though reporting cited in the content indicates Tomiris is assessed as distinct.
High-confidence behaviors described in the content include persistence via Windows Scheduled Tasks using SCHTASKS /CREATE /SC DAILY /TN StartDVL /TR "[path to self]" /ST 10:00, file collection and exfiltration over its command-and-control channel, and anti-analysis delay behavior. Tomiris can collect recent files matching a hardcoded list of extensions and upload files matching extensions such as .doc, .docx, .pdf, and .rar to its C2 server. It has also been observed packed with UPX and can sleep for at least nine minutes to evade sandbox-based analysis.
The broader Tomiris activity described in the content targets foreign ministries, intergovernmental organizations, and government entities in Russia and Central Asia, including Turkmenistan, Kyrgyzstan, Tajikistan, and Uzbekistan. Initial access is described as spear-phishing with malicious password-protected RAR archives, including executables masquerading as Word documents (*.doc.exe). Related campaigns have used implants and reverse shells in multiple languages, including C#, Rust, Go, C++, Python, VBScript, and PowerShell, and have leveraged Telegram, Discord, and TCP for C2. Additional malware and tooling mentioned in those campaigns include AdaptixC2, Distopia, JLORAT, reverse SOCKS proxies, and file-grabbing components. Reporting in the content links this activity to a Kazakhstan-based threat actor tracked by Microsoft as Storm-0473, while other firms have noted overlaps with clusters including Cavalry Werewolf, ShadowSilk, Silent Lynx, SturgeonPhisher, and YoroTrooper.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.
Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP... Tomiris can upload files matching a hardcoded set of extensions... PowerShower packed and exfiltrated .txt, .pdf, .xls or .doc files smaller than 5MB modified during the past two days.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tomiris is a multi-component malware toolkit used by the Tomiris threat actor for intelligence gathering, remote access, persistence, and lateral movement. It includes various reverse shells, downloaders, backdoors, and proxy tools written in C/C++, Rust, Go, C#, PowerShell, and Python. The malware leverages public services like Telegram and Discord for command-and-control, and is designed for stealth, long-term persistence, and targeting of government and intergovernmental organizations.
Backdoor that establishes persistence via a daily scheduled task.
Backdoor that uploads files matching hardcoded extensions to C2.
Uses long sleep (>=9 minutes) to evade sandbox analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.