The Containment Era is here. →Explore

Executive Summary

In early 2024, the Russian-speaking APT group Tomiris launched a sophisticated cyber-espionage campaign targeting government and diplomatic organizations in several CIS nations and Central Asia. Attackers leveraged new malware tools and refined tactics, initially gaining access via spear-phishing and malicious email attachments designed to exploit trust within diplomatic correspondence chains. Once inside, the group deployed covert tools for lateral movement, maintained persistence, and exfiltrated sensitive diplomatic communications and internal documents. The breach had significant operational security implications, exposing strategic discussions and potentially undermining ongoing government initiatives.

This incident exemplifies the ongoing risk posed by advanced persistent threats in geopolitical hotspots, with Tomiris demonstrating evolving tradecraft and adaptability. Organizations are urged to review east-west security, segmentation, and monitoring practices as similar espionage campaigns are increasingly targeting public sector networks.

Why This Matters Now

Tomiris’s renewed activity highlights the urgent need to defend against stealthy nation-state espionage campaigns, as traditional perimeter controls are insufficient against lateral movement and encrypted, east-west traffic. With critical government data at stake, enhancing visibility, segmentation, and detection capabilities has become a pressing requirement.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident revealed gaps in east-west traffic inspection, lateral movement prevention, and policy enforcement—highlighting the need for zero trust segmentation and advanced threat detection controls.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Enforcing zero trust segmentation, east-west monitoring, egress filtering, and encrypted traffic controls could have prevented lateral movement, detected anomalous behaviors, and blocked data exfiltration across every layer of the attack chain. CNSF controls applied in a cloud-native and hybrid context restrict attacker options, rapidly surface anomalous flows, and ensure workload, data, and access isolation.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Inline policy enforcement on access and real-time anomaly inspection thwarts rogue access attempts.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation limits permissions and lateral privilege escalation.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Inline east-west controls detect and block unauthorized workload-to-workload movement.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: Anomalous outbound connections are detected and generate incident triggers.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Unauthorized and suspicious exfiltration is blocked or quarantined at the egress point.

Impact (Mitigations)

Centralized visibility enables rapid remediation and closes persistent attacker backdoors.

Impact at a Glance

Affected Business Functions

  • Diplomatic Communications
  • Government Operations
  • Data Security
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive diplomatic communications, government documents, and personal data of officials.

Recommended Actions

  • Enforce Zero Trust segmentation across all workloads and cloud regions to prevent unauthorized lateral movement.
  • Deploy real-time, inline egress filtering and encrypted traffic inspection to identify and block covert data exfiltration attempts.
  • Establish centralized multicloud visibility for rapid detection of anomalies and automatic policy enforcement.
  • Implement continuous anomaly detection to identify and respond to C2 communications and unusual credential usage.
  • Integrate distributed policy engines (CNSF) to automate access, segmentation, and threat response across hybrid and containerized environments.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image