If you’ve been watching Tomiris over the last few years, you probably noticed a pattern: quiet operations, slow but steady evolution, heavy focus on Central Asia. What’s happening now is a noticeable shift and not a small one.
Kaspersky’s latest analysis shows Tomiris rolling out a new wave of attacks against foreign ministries, government departments, and intergovernmental orgs. Russia is the main target, but not the only one. Spear-phishing emails also hit Turkmenistan, Kyrgyzstan, Tajikistan, and Uzbekistan, each written in their local languages. So this wasn’t a sloppy spam run, they did their homework.
What really stands out this time is their use of public platforms like Telegram and Discord for command-and-control. That’s becoming a trend among APTs, but Tomiris is leaning into it harder than before. Blending malicious C2 traffic inside mainstream services is obviously a smart move, it’s harder to flag something that looks like normal user chatter.
How They Got In
Most attacks start with a simple RAR file. The email gives you the password because that little trick still works to bypass casual inspection. Inside the archive is a file pretending to be a Word document but is actually an executable.
Open it, and you get:
1. a C/C++ reverse shell,
2. system info collection,
3. connection to a C2 server,
4. and then it pulls down something like AdaptixC2.
A Mix-and-Match Toolkit
The attackers don’t rely on one programming language or implant. They spread the stack across Rust, Python, C#, Go, PowerShell, whatever fits the job. Some highlights:
1. A Rust downloader that quietly fires system info to a Discord webhook, then pulls more payloads.
2. A Python reverse shell (also Discord-based) that can run commands and send results back.
3. Another Python backdoor built on the dystopia-c2 project, this one calling home to Telegram.
4. Multiple custom reverse shells — C#, Rust, Go — each doing variations of command execution.
5. Modified SOCKS proxies (C++ and Go versions) with the debug messages stripped out so they’re less noisy.
So What’s the Goal?
Intelligence gathering. Same focus Tomiris has had for years. Long-term access, steady exfiltration, minimal noise.
A lot of people used to lump Tomiris in with Turla or even APT29 because of some overlaps in older toolsets. But the more this group evolves, the more it looks like its own operation. Microsoft linked them to a Kazakhstan-based actor called Storm-0473. Others call similar clusters SturgeonPhisher, Silent Lynx, ShadowSilk… the naming gets messy, but most of the intel points to the same place: regional espionage, not global chaos.
The 2025 campaign shows a group that’s maturing. They’re focusing on stealth, persistence, and not drawing attention. And with C2 traffic hidden inside huge public platforms, they get a lot of cover for free.
Defenders are going to have a harder time spotting these operations unless they’re paying attention to subtle behavioral patterns rather than chasing signatures.
Source: The Hacker News