Also known as: DustSquad, Nomadic Octopus
Nomadic Octopus is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments, diplomatic missions, and individuals, since at least 2014. Nomadic Octopus has been observed conducting campaigns involving Android and Windows malware, mainly using the Delphi programming language, and building custom variants.(Citation: Security Affairs DustSquad Oct 2018)(Citation: Securelist Octopus Oct 2018)(Citation: ESET Nomadic Octopus 2018)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Nomadic Octopus is a Russian-speaking cyber espionage threat group targeting Central Asian governments, diplomatic missions, and individuals since at least 2014. Known for using custom Android and Windows malware built with the Delphi programming language, the group has demonstrated sophisticated capabilities tailored to espionage objectives.
Goals & Targeting
Nomadic Octopus's primary motivation appears to be espionage, with a focus on compromising diplomatic and governmental entities in Central Asia. By targeting these sectors, the group likely seeks to obtain classified or sensitive data that could provide geopolitical advantages to its sponsors. The geographic focus on Russia and Central Asian countries aligns with potential state-backed operations aiming to influence regional dynamics.
Enhanced Description
Nomadic Octopus is an active cyber espionage threat actor primarily targeting Central Asian countries, including local governments, diplomatic missions, and individuals. The group has been observed since at least 2014, employing a variety of tactics involving Android and Windows-based malware. These tools are often custom-built using the Delphi programming language, showcasing a focus on evading detection while maintaining functionality. The actor has demonstrated persistence in targeting the government sector, suggesting a strategic intent to gather sensitive information for espionage purposes.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Nomadic Octopus has conducted long-term campaigns targeting Central Asian governments, indicating a patient and strategic approach. The group's use of custom malware suggests a high level of technical expertise tailored to specific operations. Campaign patterns include the deployment of malicious files through spear-phishing emails, often leveraging Windows PowerShell or command-line tools for execution.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data on Nomadic Octopus is limited in detail, with most information derived from indirect links to campaigns. While the group's TTPs are partially understood, including their use of Delphi-based malware and spear-phishing tactics, there are gaps in understanding their complete operational framework or exact affiliations.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
7
Techniques
1
Tools
0
Campaigns
0
IOCs
0
Observed Data
4
Tactics