The Containment Era is here. →Explore

Executive Summary

In late 2025, the state-sponsored threat actor Tomiris escalated its attacks against government entities and intergovernmental organizations, primarily in Russia and neighboring regions. The group notably shifted its tactics by deploying custom remote access implants that leveraged public cloud services, such as Telegram and Discord, as command-and-control (C2) channels. This allowed Tomiris to disguise their network traffic among legitimate service use, evading conventional perimeter defenses and security controls. The compromise enabled attackers to maintain persistent access, deploy additional payloads, and potentially exfiltrate sensitive diplomatic and policy data.

This incident is significant due to its demonstration of the evolving sophistication in APT tactics: the use of ubiquitous public platforms for C2, making detection and attribution harder. It also highlights the urgency for zero trust architectures, enhanced traffic monitoring, and cloud-centric security controls as industries face an increase in nation-state and intelligence-motivated threats.

Why This Matters Now

Tomiris’s adoption of public-service-based implants represents a broader trend among advanced threat actors who seek stealth by blending malicious traffic with popular, trusted cloud communication apps. Many governments and enterprises are now especially vulnerable due to increased reliance on cloud collaboration platforms, underscoring the urgent need for continuous monitoring, cloud-aware segmentation, and adaptive egress policies.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attack highlighted deficiencies in east-west traffic visibility, cloud service policy enforcement, and segmentation controls, particularly regarding unsanctioned and encrypted communications using public services.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Applying zero trust network segmentation, workload isolation, real-time egress policy enforcement, and advanced threat detection would have thwarted or significantly limited Tomiris’ ability to persist, move laterally, exfiltrate data, and maintain C2. CNSF-aligned controls restrict lateral movement, enforce least privilege, and provide inline inspection to disrupt covert channels over public services.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Blocked malicious inbound traffic to cloud services, reducing the attack surface.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Confined role access and limited privilege escalation beyond initial breach point.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Blocked unauthorized lateral traffic between workloads and across regions.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Blocked outbound connections to unauthorized public SaaS and C2 domains.

Exfiltration

Control: Encrypted Traffic (HPE)

Mitigation: Prevented visibility gaps by providing high-performance encrypted traffic inspection and secure data transfer.

Impact (Mitigations)

Enabled rapid detection and containment of persistent threats to limit operational impact.

Impact at a Glance

Affected Business Functions

  • Government Communications
  • Diplomatic Correspondence
  • Intergovernmental Operations
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive diplomatic communications and government documents due to unauthorized remote access established by the Tomiris APT group.

Recommended Actions

  • Enforce network-level zero trust segmentation to isolate workloads and minimize lateral movement pathways.
  • Apply stringent outbound egress controls to limit access to only sanctioned domains and services, preventing covert C2 and exfiltration.
  • Deploy real-time threat detection and anomaly response to identify suspicious behaviors and compromised endpoints promptly.
  • Ensure encryption and inspection capabilities are in place to catch and control unauthorized data flows, even over encrypted channels.
  • Centralize visibility and governance across multicloud and hybrid environments to rapidly detect, investigate, and respond to advanced persistent threats.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image