Executive Summary
In early 2024, the Russian-speaking APT group Tomiris launched a sophisticated cyber-espionage campaign targeting government and diplomatic organizations in several CIS nations and Central Asia. Attackers leveraged new malware tools and refined tactics, initially gaining access via spear-phishing and malicious email attachments designed to exploit trust within diplomatic correspondence chains. Once inside, the group deployed covert tools for lateral movement, maintained persistence, and exfiltrated sensitive diplomatic communications and internal documents. The breach had significant operational security implications, exposing strategic discussions and potentially undermining ongoing government initiatives.
This incident exemplifies the ongoing risk posed by advanced persistent threats in geopolitical hotspots, with Tomiris demonstrating evolving tradecraft and adaptability. Organizations are urged to review east-west security, segmentation, and monitoring practices as similar espionage campaigns are increasingly targeting public sector networks.
Why This Matters Now
Tomiris’s renewed activity highlights the urgent need to defend against stealthy nation-state espionage campaigns, as traditional perimeter controls are insufficient against lateral movement and encrypted, east-west traffic. With critical government data at stake, enhancing visibility, segmentation, and detection capabilities has become a pressing requirement.
Attack Path Analysis
The Tomiris group initiated their campaign against government entities by exploiting email-based phishing and leveraging compromised credentials for initial access. They escalated privileges within cloud and hybrid environments before conducting lateral movement to access additional sensitive workloads and resources. Attackers established persistent communication with external C2 infrastructure through covert channels. Sensitive data was exfiltrated via encrypted and unmonitored outbound paths. The operation culminated in the theft of government information and long-term espionage objectives, with minimal disruption but sustained risk.
Kill Chain Progression
Initial Compromise
Description
Attackers used spear phishing or social engineering to obtain valid credentials, gaining unauthorized cloud access.
Related CVEs
CVE-2023-23397
CVSS 9.8A privilege escalation vulnerability in Microsoft Outlook allows an attacker to access a user's Net-NTLMv2 hash, leading to potential NTLM relay attacks.
Affected Products:
Microsoft Outlook – 2013 SP1, 2016, 2019, 2021, Office 365
Exploit Status:
exploited in the wildCVE-2023-36884
CVSS 8.8A remote code execution vulnerability in Microsoft Office and Windows HTML components allows attackers to execute arbitrary code via specially crafted documents.
Affected Products:
Microsoft Office – 2013 SP1, 2016, 2019, 2021, Office 365
Microsoft Windows – 10, 11, Server 2016, Server 2019, Server 2022
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing
Exploitation for Client Execution
Valid Accounts
Command and Scripting Interpreter
Obfuscated Files or Information
Exfiltration Over C2 Channel
System Information Discovery
Application Layer Protocol
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – User Authentication Management
Control ID: 8.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 9
CISA Zero Trust Maturity Model 2.0 – Strong Identity Verification and Policy Enforcement
Control ID: Identity Pillar: Authentication and Authorization
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Primary target of Tomiris cyber-espionage campaign against CIS governments, requiring enhanced encrypted traffic protection and zero trust segmentation capabilities.
International Affairs
Diplomatic entities face direct targeting in Central Asia operations, needing robust threat detection and secure hybrid connectivity for sensitive communications.
Computer/Network Security
Security providers must counter new Havoc tools with advanced inline IPS capabilities and multicloud visibility solutions for comprehensive threat response.
Information Technology/IT
IT infrastructure vulnerable to lateral movement attacks requires immediate implementation of east-west traffic security and Kubernetes security frameworks.
Sources
- Tomiris Unleashes 'Havoc' With New Tools, Tacticshttps://www.darkreading.com/cyberattacks-data-breaches/tomiris-unleashes-havoc-new-tools-tacticsVerified
- New Tomiris tools and techniques: multiple reverse shells, Havoc, AdaptixC2https://securelist.com/tomiris-new-tools/118143/Verified
- Tomiris APT Targets Diplomatic Entities in New Campaign Using Multi-Language Reverse Shells, Havoc and AdaptixC2 Open-Source Frameworkshttps://www.technadu.com/tomiris-apt-targets-diplomatic-entities-in-new-campaign-using-multi-language-reverse-shells-havoc-and-adaptixc2-open-source-frameworks/614742/Verified
- Tomiris Hacker Group Added New Tools and Techniques to Attack Organizations Globallyhttps://www.cryptika.com/tomiris-hacker-group-added-new-tools-and-techniques-to-attack-organizations-globally/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Enforcing zero trust segmentation, east-west monitoring, egress filtering, and encrypted traffic controls could have prevented lateral movement, detected anomalous behaviors, and blocked data exfiltration across every layer of the attack chain. CNSF controls applied in a cloud-native and hybrid context restrict attacker options, rapidly surface anomalous flows, and ensure workload, data, and access isolation.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Inline policy enforcement on access and real-time anomaly inspection thwarts rogue access attempts.
Control: Zero Trust Segmentation
Mitigation: Microsegmentation limits permissions and lateral privilege escalation.
Control: East-West Traffic Security
Mitigation: Inline east-west controls detect and block unauthorized workload-to-workload movement.
Control: Threat Detection & Anomaly Response
Mitigation: Anomalous outbound connections are detected and generate incident triggers.
Control: Egress Security & Policy Enforcement
Mitigation: Unauthorized and suspicious exfiltration is blocked or quarantined at the egress point.
Centralized visibility enables rapid remediation and closes persistent attacker backdoors.
Impact at a Glance
Affected Business Functions
- Diplomatic Communications
- Government Operations
- Data Security
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive diplomatic communications, government documents, and personal data of officials.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust segmentation across all workloads and cloud regions to prevent unauthorized lateral movement.
- • Deploy real-time, inline egress filtering and encrypted traffic inspection to identify and block covert data exfiltration attempts.
- • Establish centralized multicloud visibility for rapid detection of anomalies and automatic policy enforcement.
- • Implement continuous anomaly detection to identify and respond to C2 communications and unusual credential usage.
- • Integrate distributed policy engines (CNSF) to automate access, segmentation, and threat response across hybrid and containerized environments.



