Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Nomadic Octopus

Also known as: DustSquad, Nomadic Octopus

Description

Nomadic Octopus is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments, diplomatic missions, and individuals, since at least 2014. Nomadic Octopus has been observed conducting campaigns involving Android and Windows malware, mainly using the Delphi programming language, and building custom variants.(Citation: Security Affairs DustSquad Oct 2018)(Citation: Securelist Octopus Oct 2018)(Citation: ESET Nomadic Octopus 2018)

Goals & Targeting

Targeted Sectors

Government

Targeted Countries / Regions

RU
central_asia

AI Analysis

· 2 weeks ago

Executive Summary

Nomadic Octopus is a Russian-speaking cyber espionage threat group targeting Central Asian governments, diplomatic missions, and individuals since at least 2014. Known for using custom Android and Windows malware built with the Delphi programming language, the group has demonstrated sophisticated capabilities tailored to espionage objectives.

Goals & Targeting

Nomadic Octopus's primary motivation appears to be espionage, with a focus on compromising diplomatic and governmental entities in Central Asia. By targeting these sectors, the group likely seeks to obtain classified or sensitive data that could provide geopolitical advantages to its sponsors. The geographic focus on Russia and Central Asian countries aligns with potential state-backed operations aiming to influence regional dynamics.

Enhanced Description

Nomadic Octopus is an active cyber espionage threat actor primarily targeting Central Asian countries, including local governments, diplomatic missions, and individuals. The group has been observed since at least 2014, employing a variety of tactics involving Android and Windows-based malware. These tools are often custom-built using the Delphi programming language, showcasing a focus on evading detection while maintaining functionality. The actor has demonstrated persistence in targeting the government sector, suggesting a strategic intent to gather sensitive information for espionage purposes.

Key Capabilities

  • Custom Android malware
  • Custom Windows malware using Delphi
  • Spear-phishing campaigns
  • Malicious file distribution via email attachments

MITRE ATT&CK Tactics

Collection
Exfiltration
Lateral Movement
Defense Evasion
Credential Access

ATT&CK Techniques

T1204.002
T1036
T1059.001
T1059.003
T1566.001
T1564.003

Software / Tooling

Octopus malware
Cobalt Strike (inferred from linked TTPs)
Hidden Window technique tools

Campaigns & Victims

Nomadic Octopus has conducted long-term campaigns targeting Central Asian governments, indicating a patient and strategic approach. The group's use of custom malware suggests a high level of technical expertise tailored to specific operations. Campaign patterns include the deployment of malicious files through spear-phishing emails, often leveraging Windows PowerShell or command-line tools for execution.

IOC Patterns

  • Spearphishing attachments with malicious links
  • Malicious files dropped from compromised email accounts
  • Windows-based malware using Delphi programming language
  • Hidden window creation to avoid detection

Recommended Actions

  • Implement robust email filtering solutions to detect spear-phishing attempts.
  • Monitor for PowerShell and command-line tool activity indicative of malicious behavior.
  • Conduct regular updates and patches on all operating systems to mitigate known vulnerabilities.
  • Use endpoint detection and response (EDR) tools to identify hidden or anomalous processes.

Suggested Tags

APT
espionage
government
Central Asia
Russia

Confidence Assessment

The available data on Nomadic Octopus is limited in detail, with most information derived from indirect links to campaigns. While the group's TTPs are partially understood, including their use of Delphi-based malware and spear-phishing tactics, there are gaps in understanding their complete operational framework or exact affiliations.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. ESET Nomadic Octopus 2018 — Cherepanov, A. (2018, October 4). Nomadic Octopus Cyber espionage in Central Asia. Retrieved October 13, 2021.
  2. Securelist Octopus Oct 2018 — Kaspersky Lab's Global Research & Analysis Team. (2018, October 15). Octopus-infested seas of Central Asia. Retrieved November 14, 2018.
  3. SecurityWeek Nomadic Octopus Oct 2018 — Kovacs, E. (2018, October 18). Russia-Linked Hackers Target Diplomatic Entities in Central Asia. Retrieved October 13, 2021.
  4. Security Affairs DustSquad Oct 2018 — Paganini, P. (2018, October 16). Russia-linked APT group DustSquad targets diplomatic entities in Central Asia. Retrieved August 24, 2021.

Intel Summary

7

Techniques

1

Tools

0

Campaigns

0

IOCs

0

Observed Data

4

Tactics

Tags

APT
Government Targeting
espionage
government
Central Asia
Russia

Details

MITRE ID
G0133
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
R
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--fed4f0a2-4347-4530-b0f5-6dfd49b29172
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.