Tomiris Backdoor Trojan

General News

Summary

Infosec researchers have discovered a new backdoor Trojan named Tomiris that might have links to the infamous NOBELIUM APT (Advanced Persistent Threat) group. Tomiris attribution to NOBELIUM has not been proven conclusively; however, the threat also shares certain similarities with Kazuar, one of the backdoors linked to the Turla APT. Once redirected to the impostor page, the unsuspecting visitors were urged to download a corrupted software update carrying the Tomiris backdoor. While analyzing the behavior and underlying code of Tomiris, the researchers began noticing a lot of similarities with the second-stage malware Sunshuttle that NOBELIUM used in the SolarWinds attack. These include both threats being written in the Go programming language, using single encryption/obfuscation methods, establishing persistence via scheduled tasks, and using sleep delays to hide their intrusive activities.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M