Tomiris Shifts to Public-Service Implants for Stealthier C2 in Attacks on Government Targets
Attacks on foreign ministries, intergovernmental organizations, and Russian government bodies with the intention of establishing remote access and deploying further tools have been linked to the threat actor known as Tomiris.
These attacks indicate a major shift in Tomiris's methods, especially the increased usage of implants that utilize public services (e.g., Telegram and Discord) as command-and-control (C2) servers, Kaspersky researchers Oleg Kupreev and Artem Ushkov noted in an investigation. This strategy apparently seeks to combine malicious traffic with normal service activity to circumvent detection by security technologies.
The cybersecurity business stated more than 50% of the spear-phishing emails and decoy files used in the operation used Russian names and contained Russ...

