Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Storm-0473

Also known as: UNC2849, other aliases, several other aliases, Chafer, Tomiris, Jumpy Pisces, OilRig, ALPHV, Gleaming Pisces, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, BokBot, Gold Southfield, PlayCrypt, SideWinder, APT-C-17, Rattlesnake, APT39, Sodinokibi, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Turla

Description

Storm-0473 (Tomiris) is a threat actor that has been active since at least 2019. They primarily target government and diplomatic entities in the Commonwealth of Independent States region, with occasional victims in other regions being foreign representations of CIS countries. Tomiris uses a wide variety of malware implants, including downloaders, backdoors, and file stealers, developed in different programming languages. They employ various attack vectors such as spear-phishing, DNS hijacking, and exploitation of vulnerabilities. There are potential ties between Tomiris and Turla, but they are considered separate threat actors with distinct targeting and tradecraft by Kaspersky.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Healthcare
Telecommunications
Critical infrastructure
Education
Manufacturing
Media
Non profit
Energy
Maritime
Retail
Hospitality
Aerospace
Think tank
Transportation
Gaming
Utilities
Information technology
Aviation
Legal services
Mining
Oil gas
Nuclear
Entertainment
Food agriculture
Construction

Targeted Countries / Regions

RU
UA
IN
CN
IR
US
PK
KP
KR
TW
AE
AU
SA
BY
BR
GB
MX
VN
CA
AZ
DE
TR
ES
NL
PL

AI Analysis

· 1 week ago

Executive Summary

Storm-0473 (Tomiris) is an active threat actor targeting government and diplomatic entities in the Commonwealth of Independent States (CIS) region since at least 2019. The group employs a variety of malware, including downloaders, backdoors, and file stealers, leveraging attack vectors such as spear-phishing and DNS hijacking. Despite potential ties to Turla, Tomiris operates distinctly with its own tradecraft.

Goals & Targeting

Storm-0473 is likely focused on gather intelligence from government and diplomatic targets within the CIS region. Their selection of victims suggests a strategic interest in national security and foreign policy communications. The group's regional focus, particularly targeting diplomatic representations of CIS countries elsewhere, indicates an effort to influence or monitor international relations involving these states.

Enhanced Description

Storm-0473, also known as Tomiris, is a cyber threat actor that has been operational since at least 2019. This group primarily targets government and diplomatic entities within the Commonwealth of Independent States (CIS) region, with occasional victims being foreign representations of these countries outside the CIS. Tomiris is notable for its use of diverse malware, including downloaders, backdoors, and file stealers, developed in various programming languages. The group's attack methods include spear-phishing campaigns and exploitation of vulnerabilities. Tomiris' activities have raised speculation about potential ties to Turla, but according to Kaspersky analysis, they are considered separate entities with distinct targeting and operational techniques.

Key Capabilities

  • Advanced malware development across multiple programming languages
  • Spear-phishing attacks using malicious email campaigns
  • DNS hijacking for potential command and control (C2) infrastructure
  • Exploitation of software vulnerabilities

MITRE ATT&CK Tactics

Reconnaissance
Initial Access
Defense Evasion
Credential Access
Discovery

ATT&CK Techniques

T1059
T1055
T1566

Software / Tooling

Custom malware (downloaders, backdoors)
Spear-phishing emails
C2 infrastructure

Campaigns & Victims

Storm-0473 has demonstrated persistent activity targeting government and diplomatic sectors over multiple years. The group's campaigns often involve long-term access using backdoors and custom malware to exfiltrate sensitive data. Their operational tempo appears methodical, focusing on maintaining persistence within targeted networks rather than rapid turnover of attacks. Notable past operations include numerous breaches of government entities in CIS countries and their foreign diplomatic missions.

IOC Patterns

  • Spear-phishing emails with malicious attachments or links
  • Malicious C2 communication over DNS (fast-flux domains)
  • Staging infrastructure on known or suspected bulletproof hosting services
  • Use of custom malware in various programming languages

Recommended Actions

  • Implement robust email filtering and anti-phishing solutions to detect spear-phishing attempts.
  • Monitor network traffic for C2 activities using DNS, particularly fast-flux domains.
  • Conduct regular vulnerability assessments and patch management to mitigate exploit-based attacks.
  • Use endpoint detection and response (EDR) tools to identify and respond to malware activity.

Suggested Tags

APT
CIS-targeted
Government Espionage
Malware
State-sponsored

Confidence Assessment

High confidence in Storm-0473's existence and targeting profile based on Kaspersky analysis. Some uncertainty exists regarding primary motivation and exact operational framework, as well as potential coordination with other actors like Turla.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.huntress.com — Cited by web research for: other aliases
  2. www.microsoft.com — Cited by web research for: OilRig
  3. attack.mitre.org — Cited by web research for: T9000
  4. unit42.paloaltonetworks.com — Cited by web research for: T1486
  5. attack.mitre.org — Cited by web research for: T1071.002

Intel Summary

21

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

8

Tactics

Tags

Phishing
Backdoor / C2
Government Targeting
APT
CIS-targeted
Government Espionage
Malware
State-sponsored

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.