The Tomiris advanced persistent threat (APT) group has shifted its tactics to leverage public services such as Telegram and Discord as command-and-control (C2) channels in cyber-espionage campaigns targeting government entities and diplomatic organizations. This approach is designed to blend malicious traffic with legitimate service activity, making detection by security tools more difficult. The group has primarily targeted Russian-speaking users and entities, as well as government organizations in Central Asia, using spear-phishing emails and decoy files tailored to the local languages. The attacks have involved the deployment of custom implants, reverse shells, and open-source C2 frameworks like Havoc and AdaptixC2 to facilitate post-exploitation activities.
Attribution analysis links Tomiris to intelligence-gathering operations in Central Asia, with some overlap in tooling and tactics with other Russian-linked threat actors, though Tomiris is assessed as a distinct group. The adoption of "polyglot" strategies—using multiple file formats and covert C2 channels—demonstrates the group's operational sophistication and adaptability. Security researchers emphasize the importance of monitoring public service traffic and enhancing detection capabilities to counter these evolving threats.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
On December 1, 2025, multiple outlets reported research describing Tomiris's increased sophistication, long-term persistence, and tailored attacks on diplomatic and government targets. The reporting also noted overlap in some tooling with Turla while assessing Tomiris as a separate threat actor and warned defenders to monitor trusted applications like Telegram more closely.
Tomiris deployed malware components written in multiple programming languages, including Rust-based tools, reverse shells, and implants, alongside open-source frameworks such as AdaptixC2 and Havoc. The tooling supported system reconnaissance, file theft, remote command execution, screen monitoring, and deeper network compromise while improving operational flexibility and evasion.
In the campaign, Tomiris shifted command-and-control and some data exfiltration activity to public messaging platforms including Telegram and Discord to blend malicious traffic with legitimate services. Researchers observed Telegram bot-based tooling and exfiltration to private Discord channels as part of the group's stealthier operations.
Tomiris began targeting government and diplomatic entities in Russia, Central Asia, and other CIS member states with spear-phishing emails disguised as official communications. The lures delivered password-protected RAR or archive files containing malicious documents to establish initial access for espionage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcethehackernews.com
Open sourcescworld.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.