{"id":55546,"date":"2023-04-28T09:47:53","date_gmt":"2023-04-28T01:47:53","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=55546"},"modified":"2023-04-28T09:47:56","modified_gmt":"2023-04-28T01:47:56","slug":"kaspersky-investigates-tomiris-apt-group-targeting-government-entities-in-cis","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2023\/04\/28\/kaspersky-investigates-tomiris-apt-group-targeting-government-entities-in-cis\/","title":{"rendered":"Kaspersky investigates Tomiris APT group targeting government entities in CIS"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Kaspersky has released a new investigation on Tomiris APT group that focuses on intelligence gathering in Central Asia. This Russian-speaking actor uses a wide variety of malware implants developed at a rapid pace and in all programming languages imaginable, presumably in order to obstruct attribution. What drew the researchers\u2019 special attention is that Tomiris deploys malware that was previously linked to Turla, another notorious APT group.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kaspersky first publicly described <a rel=\"noreferrer noopener\" href=\"https:\/\/securelist.com\/darkhalo-after-solarwinds-the-tomiris-connection\/104311\/\" target=\"_blank\">Tomiris<\/a> in September 2021, following the investigation of a DNS-hijack against a government organization in the Commonwealth of Independent States (CIS). Back then, the researchers had noted inconclusive similarities with the SolarWinds incident. They continued to track Tomiris as a separate threat actor over several new attack campaigns between 2021 and 2023, and Kaspersky\u2019s telemetry allowed to shed light on the group\u2019s toolset and its possible connection to Turla.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The threat actor targets government and diplomatic entities in the CIS with the final aim to steal internal documents. The occasional victims discovered in other regions (such as the Middle East or South-East Asia) turn out to be foreign representations of CIS countries, illustrating Tomiris\u2019s narrow focus.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tomiris goes after its victims using a wide variety of attack vectors: spear-phishing emails with malicious content attached (password-protected archives, malicious documents, weaponized LNKs), DNS hijacking, exploitation of vulnerabilities (specifically <a rel=\"noreferrer noopener\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-26855\" target=\"_blank\">ProxyLogon<\/a>), suspected drive-by downloads and other \u201ccreative\u201d methods.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/mail.google.com\/mail\/u\/1?ui=2&amp;ik=3c53ca4039&amp;attid=0.3&amp;permmsgid=msg-f:1764377677054894964&amp;th=187c5426327c6374&amp;view=fimg&amp;fur=ip&amp;sz=s0-l75-ft&amp;attbid=ANGjdJ81fuUgRuRDIqbK4Ymt5SFCplTSKkuOfmTd_KJFkOmya_65TJvyVY05B7tZsOCJI_u4qmLlbTbN4kbxlWp6zmOVUuQpmfBP7XNssR2CGwmSFKH-6fR-mclw2ts&amp;disp=emb\" alt=\"image.png\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Relationships between Tomiris tools. Arrows indicate a distribution link (parent distributed, downloaded or contained child)<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What makes most recent Tomiris\u2019 operations special is that, with medium-to-high confidence, they leveraged KopiLuwak and TunnusSched malware that were previously connected to Turla. However, despite sharing this toolkit, Kaspersky\u2019s latest research explains that Turla and Tomiris are very likely separate actors that could be exchanging tradecraft.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tomiris is undoubtedly Russian-speaking, but its targeting and tradecrafts are significantly at odds with what has been observed for Turla. In addition, Tomiris\u2019s general approach to intrusion and limited interest in stealth do not match documented Turla tradecraft. However, Kaspersky\u2019s researchers believe that tools sharing is a potential proof of some cooperation between Tomiris and Turla, the extent of which is difficult to assess. In any case, depending on when Tomiris started using KopiLuwak, a number of campaigns and tools believed to be linked to Turla may in fact need to be re-evaluated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cOur research shows that the use of KopiLuwak or TunnusSched is now insufficient to link cyberattacks to Turla. To the best of our knowledge, this toolset is currently leveraged by Tomiris, which we strongly believe is distinct from Turla \u2013 although both actors likely cooperated at some point. Looking at tactics and malware samples only gets us so far, and we are often reminded that threat actors are subject to organizational and political constraints. This investigation illustrates the limits of technical attribution that we can only overcome through intelligence sharing.\u201d comments Pierre Delcher, senior security researcher at Kaspersky\u2019s Global Research and Analysis Team (GReAT).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Read the full report about the Tomiris APT group on <a rel=\"noreferrer noopener\" href=\"https:\/\/securelist.com\/tomiris-called-they-want-their-turla-malware-back\/109552\/\" target=\"_blank\">Securelist.<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky researchers recommend implementing the following measures:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Provide your SOC team with access to the latest threat intelligence (TI). <a rel=\"noreferrer noopener\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/threat-intelligence\" target=\"_blank\">The Kaspersky Threat Intelligence Portal<\/a> is a single point of access for the company\u2019s TI, providing cyberattack data and insights gathered by Kaspersky spanning over 20 years.&nbsp;<\/li>\n\n\n\n<li>Upskill your cybersecurity team to tackle the latest targeted threats with&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/xtraining.kaspersky.com\/?utm_source=pr-media&amp;utm_medium=partner&amp;utm_campaign=gl_xtr-gen-pr_je0066&amp;utm_content=sm-post&amp;utm_term=gl_pr-media_organic_66jpzgkgnjbgdrn&amp;redef=1&amp;THRU&amp;reseller=gl_xtr-gen-pr_acq_ona_smm__onl_b2b_pr-media_post_______\" target=\"_blank\">Kaspersky online training<\/a>&nbsp;developed by GReAT experts.<\/li>\n\n\n\n<li>For endpoint level detection, investigation, and timely remediation of incidents, implement EDR solutions such as&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/endpoint-detection-response-edr\" target=\"_blank\">Kaspersky Endpoint Detection and Response<\/a>.<\/li>\n\n\n\n<li>In addition to adopting essential endpoint protection, implement a corporate-grade security solution that detects advanced threats on the network level at an early stage, such as&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/anti-targeted-attack-platform\" target=\"_blank\">Kaspersky Anti Targeted Attack Platform<\/a>.<\/li>\n\n\n\n<li>As many targeted attacks start with phishing or other social engineering techniques, introduce security awareness training and teach practical skills to your team \u2013 for example, through the&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/www.kaspersky.com\/small-to-medium-business-security\/security-awareness-platform\" target=\"_blank\">Kaspersky Automated Security Awareness Platform<\/a>.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky first publicly described Tomiris in September 2021, following the investigation of a DNS-hijack against a government organization in the Commonwealth of Independent States (CIS). <\/p>\n","protected":false},"author":6,"featured_media":55558,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[286,101,54,2103],"class_list":["post-55546","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-it-security","tag-kaspersky","tag-security","tag-security-breach"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/55546","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=55546"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/55546\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/55558"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=55546"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=55546"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=55546"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}