Tomiris Backdoor Trojan
Summary
Infosec researchers have discovered a new backdoor Trojan named Tomiris that might have links to the infamous NOBELIUM APT (Advanced Persistent Threat) group. Tomiris attribution to NOBELIUM has not been proven conclusively; however, the threat also shares certain similarities with Kazuar, one of the backdoors linked to the Turla APT. Once redirected to the impostor page, the unsuspecting visitors were urged to download a corrupted software update carrying the Tomiris backdoor. While analyzing the behavior and underlying code of Tomiris, the researchers began noticing a lot of similarities with the second-stage malware Sunshuttle that NOBELIUM used in the SolarWinds attack. These include both threats being written in the Go programming language, using single encryption/obfuscation methods, establishing persistence via scheduled tasks, and using sleep delays to hide their intrusive activities.