Also known as: UNC2849, other aliases, several other aliases, Chafer, Tomiris, Jumpy Pisces, OilRig, ALPHV, Gleaming Pisces, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, BokBot, Gold Southfield, PlayCrypt, SideWinder, APT-C-17, Rattlesnake, APT39, Sodinokibi, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Turla
Storm-0473 (Tomiris) is a threat actor that has been active since at least 2019. They primarily target government and diplomatic entities in the Commonwealth of Independent States region, with occasional victims in other regions being foreign representations of CIS countries. Tomiris uses a wide variety of malware implants, including downloaders, backdoors, and file stealers, developed in different programming languages. They employ various attack vectors such as spear-phishing, DNS hijacking, and exploitation of vulnerabilities. There are potential ties between Tomiris and Turla, but they are considered separate threat actors with distinct targeting and tradecraft by Kaspersky.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm-0473 (Tomiris) is an active threat actor targeting government and diplomatic entities in the Commonwealth of Independent States (CIS) region since at least 2019. The group employs a variety of malware, including downloaders, backdoors, and file stealers, leveraging attack vectors such as spear-phishing and DNS hijacking. Despite potential ties to Turla, Tomiris operates distinctly with its own tradecraft.
Goals & Targeting
Storm-0473 is likely focused on gather intelligence from government and diplomatic targets within the CIS region. Their selection of victims suggests a strategic interest in national security and foreign policy communications. The group's regional focus, particularly targeting diplomatic representations of CIS countries elsewhere, indicates an effort to influence or monitor international relations involving these states.
Enhanced Description
Storm-0473, also known as Tomiris, is a cyber threat actor that has been operational since at least 2019. This group primarily targets government and diplomatic entities within the Commonwealth of Independent States (CIS) region, with occasional victims being foreign representations of these countries outside the CIS. Tomiris is notable for its use of diverse malware, including downloaders, backdoors, and file stealers, developed in various programming languages. The group's attack methods include spear-phishing campaigns and exploitation of vulnerabilities. Tomiris' activities have raised speculation about potential ties to Turla, but according to Kaspersky analysis, they are considered separate entities with distinct targeting and operational techniques.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Storm-0473 has demonstrated persistent activity targeting government and diplomatic sectors over multiple years. The group's campaigns often involve long-term access using backdoors and custom malware to exfiltrate sensitive data. Their operational tempo appears methodical, focusing on maintaining persistence within targeted networks rather than rapid turnover of attacks. Notable past operations include numerous breaches of government entities in CIS countries and their foreign diplomatic missions.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Storm-0473's existence and targeting profile based on Kaspersky analysis. Some uncertainty exists regarding primary motivation and exact operational framework, as well as potential coordination with other actors like Turla.
No campaigns linked yet.
No observed data linked yet.
21
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
8
Tactics