Technical Release: Tomiris Expands Its Cyber Arsenal Across CIS and Central Asia

Listen to this Post

Featured Image

Introduction: Rising Shadows Over Diplomatic Networks

A silent escalation is unfolding across the digital borders of Central Asia. Behind routine diplomatic correspondence and intergovernmental communication, one Russian-speaking espionage group has sharpened its craft, expanded its toolkit, and quietly embedded itself deeper into the political machinery of the Commonwealth of Independent States. This is the new chapter of Tomiris, a threat actor defined not by elegance, but by persistence, improvisation, and an uncanny ability to reshape its tactics faster than defenders can react. What follows is a chronological, detailed, and human-centered look at how this group has evolved and why its latest campaign represents one of the most disruptive movements in regional cyber espionage today.

Expanded the Original Report

Tomiris’ Escalating Campaign

The Russian-speaking Tomiris group has launched a new wave of cyber-espionage activity targeting foreign ministries, diplomatic missions, and government institutions across CIS countries and Central Asia. Researchers at Kaspersky, monitoring the threat actor since 2021, observed that beginning early 2025 Tomiris deployed an updated suite of tools designed to infiltrate high-value political infrastructures.

Core Tactical Evolutions

Kaspersky highlighted two central tactical changes. First, Tomiris has started routing command-and-control traffic through Telegram and Discord. By hiding malicious communication inside popular platforms, the group makes detection far harder for enterprise networks that routinely allow these services. Second, Tomiris is now crafting implants in multiple programming languages including Go, Rust, C, C++, C sharp, Python and others, enabling adaptable malware capable of bypassing varied defensive environments. These implants deliver secondary payloads such as Havoc and AdaptixC2, open source frameworks that allow the attackers hands-on control of compromised systems.

Stealth Through Diversity

Kaspersky noted that these tactics reflect a commitment to stealth and long-term persistence. Routing C2 through public services and using multi-language malware both signal a strategic emphasis on evading modern detection mechanisms. Enterprises relying on signature-based defenses face significant challenges, making behavioral analysis and deep network inspection essential.

APT Profile and Motivations

Tomiris is classified as an advanced persistent threat focused on stealing internal government and diplomatic documents from CIS and Central Asian states. The group is known for repetition rather than precision, frequently cycling through disposable malware variants until one succeeds. Though less refined than other nation-state groups, Tomiris remains dangerous because of its relentless brute-force style and disregard for operational stealth.

Connections to Turla

While Tomiris has used some tools historically associated with Turla, a Russian FSB-linked group, Kaspersky maintains that they remain separate entities. Similarities stem from overlapping tools, not shared command structures. Their targeting choices and methodologies differ enough to classify them independently.

Infection Chain Mechanics

As seen in past operations, Tomiris begins its intrusion process via phishing emails that contain password-protected archives. The passwords are included inside the email body, and the attached files masquerade as legitimate documents through manipulated filenames padded with empty spaces. This tactic hides the executable extension on preview, tricking victims into opening them.

Localized Targeting

Over half of the phishing content analyzed by Kaspersky was in Russian, though customized lures were also prepared in the primary languages of Turkmenistan, Tajikistan, Uzbekistan, and Kyrgyzstan. This localization reflects an adaptive social engineering strategy embedded within Tomiris operations.

Tools and Backdoors

Among the new tools discovered, one Rust-based component gathers system information, hunts for files with extensions such as pdf and jpg, and sends stolen data to Discord servers controlled by the attackers. Another Python-based tool collects files of specific types, compresses them, and uploads them to C2 servers. Additional backdoors support remote command execution, file management, process termination, and even lateral movement using custom proxy utilities.

Detection Challenges

The use of Telegram and Discord as C2 channels introduces severe detection difficulties. Because many organizations whitelist these platforms for legitimate use, identifying malicious activity hidden inside encrypted, trusted traffic requires deeper inspection capabilities. Traditional perimeter defenses are inadequate, forcing security teams to rely on behavioral analytics and advanced anomaly detection systems to spot deviations in network behavior.

What Undercode Say:

Analytical Breakdown and Strategic Implications

Tomiris’ new operational cycle marks a critical turning point in regional cyber-espionage strategy. The shift toward embedding C2 traffic inside mainstream communication platforms signals an acknowledgment of modern enterprise realities. Organizations today depend heavily on public messaging services, which naturally creates a blind spot that Tomiris is exploiting with remarkable efficiency. By weaponizing whitelisted applications, the group transforms trust into camouflage and turns network hygiene into a vulnerability.

The multi-language toolchain is equally significant. Writing malware in Go, Rust, C, and Python is not just a method of agility; it is a psychological strategy designed to overwhelm defenders. Every new language variant forces analysts to adapt their reverse-engineering approach. This is warfare through diversity, where the sheer variety of tools becomes an attack vector. It also implies that Tomiris may be operating as a decentralized entity, with different developers contributing specialized modules instead of following a rigid, hierarchical system.

Tomiris’ brute-force persistence remains one of its most defining traits. Unlike highly stealthy APTs that rely on precision, Tomiris thrives on iterative trial and error. It resembles a storm: messy, volatile, but eventually effective. In environments with uneven security adoption, even basic phishing coupled with rotated malware variants becomes a long-term threat. The group’s willingness to sacrifice implants quickly and repeatedly also indicates access to plentiful development resources.

Their geographic and linguistic targeting reinforces the political nature of the campaign. Customizing phishing content in Tajik, Uzbek, Kyrgyz, and Turkmen languages suggests deep reconnaissance and a keen understanding of regional government workflows. This is not opportunistic cybercrime. It is state-aligned intelligence gathering focused on diplomatic communication streams and internal political documentation.

The overlap with Turla should not be underestimated, even if Kaspersky distinguishes the groups. Tool sharing in the Russian cyber ecosystem is often a sign of tacit coordination or shared logistical support. Though operational priorities differ, any potential link increases strategic complexity. If Tomiris continues evolving its tradecraft while borrowing components from more sophisticated actors, the blend could lead to higher-impact operations in future cycles.

Defensively, the reliance on Telegram and Discord C2 infrastructure forces a reevaluation of network trust boundaries. Enterprises can no longer depend on binary allow-deny models. If everyday collaboration tools serve as carrier channels for espionage payloads, defenders must adopt behavioral baselines that detect subtle changes in usage patterns. The battle is shifting toward dynamic monitoring rather than static firewalling.

Finally, the discovery of lateral movement tools, specialized proxies, and file-harvesting automation suggests a maturing kill chain. Tomiris is no longer a group defined solely by persistence. It is becoming faster, stealthier, and more modular, with an ecosystem of implants engineered for specific phases of intrusion. The next stage of its evolution will likely involve more automation and even tighter blending with legitimate cloud services.

Fact Checker Results

Accuracy Snapshot

The tactical updates described in the report align with verifiable research by Kaspersky. ✅

The claims regarding tool overlaps between Tomiris and Turla are consistent with previous assessments but remain inconclusive. ❌

The details on infection techniques and multilingual targeting match established APT behaviors in the region. ✅

Prediction

Forward-Looking Assessment

Tomiris is likely to broaden its reliance on mainstream communication platforms, integrating emerging regional apps into its C2 infrastructure. 📊
Future payloads may further adopt AI-assisted automation for file selection and lateral movement. 📊
As geopolitical tensions rise across Central Asia, Tomiris will likely intensify its focus on diplomatic networks and cross-border information flows. 📊

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.darkreading.com
Extra Source Hub (Possible Sources for article):
https://www.quora.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon