New Tomiris tools and techniques: multiple reverse shells, Havoc, AdaptixC2
· Published 28/11/2025 08:31 · Modified 21/12/2025 18:14
Essential information
- Published
- 28/11/2025 08:31
- Modified
- 21/12/2025 18:14
- Tags
- 2025-11-28 adaptixc2 apt discord distopia backdoor government targets havoc jlorat multi-language malware reverse shells telegram tomiris c# reverseshell tomiris c# telegram reverseshell tomiris c++ reversesocks tomiris c/c++ reverseshell tomiris go reverseshell tomiris go reversesocks tomiris powershell telegram backdoor tomiris python discord reverseshell tomiris python filegrabber tomiris python telegram reverseshell tomiris rust downloader tomiris rust reverseshell
- Related entities
- 66 observables, 1 intrusion sets (apt), 17 techniques (mitre), 16 malware, 6 others
Description
Kaspersky researchers uncovered new malicious operations by the Tomiris threat actor targeting foreign ministries, intergovernmental organizations, and government entities. The attacks, which began in early 2025, show a shift in tactics with increased use of implants leveraging public services like Telegram and Discord as command-and-control servers. The group employs various programming languages including Go, Rust, C/C#/C++, and Python to develop reverse shell tools. Some infections lead to the deployment of open-source post-exploitation frameworks such as Havoc and AdaptixC2. The campaign primarily focuses on Russian-speaking users and entities, with additional targets in Central Asian countries.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Observables (66)
88.214.25.24982.115.223.21064.7.199.193192.153.57.9188.127.231.13678.128.112.20985.209.128.171188.127.251.146188.127.225.191206.188.196.191185.173.37.67188.127.227.226192.165.32.7891.219.148.9394.198.52.20096.9.124.20782.115.223.21882.115.223.78193.149.129.11388.214.26.37192.153.57.18994.198.52.21077.232.39.4777.232.42.107185.244.180.169https://sss.qwadx.com/netexit.rarhttps://sss.qwadx.com/winsrv.exehttp://62.113.115.89/homepage/infile.phphttp://82.115.223.78/private/dwm.exehttp://188.127.251.146:8080/sbchost.rarhttp://82.115.223.78/private/svchost.exehttp://192.153.57.9/private/svchost.exehttp://195.2.79.245/winload.rarhttps://docsino.ru/wp-content/private/winupdate.exehttp://195.2.79.245/winupdate.exehttp://195.2.79.245/service.exehttp://195.2.79.245/winload.exehttps://sss.qwadx.com/winload.exehttp://82.115.223.78/private/spoolsvc.exehttp://195.2.79.245/firefox.exehttp://188.127.251.146:8080/sxbchost.exehttp://82.115.223.78/private/sysmgmt.exehttps://sss.qwadx.com/AkelPad.exehttps://docsino.ru/wp-content/private/alone.exehttp://89.110.98.234/winload.exehttp://88.214.25.249:443/netexit.rarhttp://82.115.223.78/private/msview.exehttp://89.110.98.234/winload.rarhttp://85.209.128.171:8000/AkelPad.rarhttps://sss.qwadx.com/12345.exe148a42ccaa97c2e2352dbb207f07932141d5290d4c3b57f61a780f9168783edae46a04b9950a29e8638d5ff6508db94bf2811d613995a964cb5953922b02b0ac4420148744799563bd559cd6bd42ac10ffe0cc2895c0f5366288272d3b947eecec80e96e3d15a215d59d1095134e7131114f669ebc406c6ea1a709003d3f6f17ab0ad77a341b12cfc719d10e0fc45a6613f41b2b3f6ea963ee6572cf02b41f4dbe519d0acca77865ed569f16774e7ecb096a5a6ed0b6fe70ab5d5b438964cc118e7fb9f6acfb9b08fb424ff5772c46011a92d80191e7736010380443a46e695cb4add80567c915eadffd00f022ca738a7eb4552aedad9da8ea658f04ca693bfc4f17a7f8d2cec5c2206c3cba92967b4b499f0d223748d3b34f9ec4981461d288d59577c808e5fc0c67cfaf17fb64cd92c2ed4cb3b6c6bd7110836c8b4b8561707084f06f2d8613dfe418b242c43060ae578e7166ce5aeed2904a8327cd98dbdfcc84bfdb6e996b67d8bc812cf08674e8eca6906b53c98df195ed99ac5ec14a06ae562641ccd56f6735cb93eb4c6beba1f40921281a103f2c9e7f339bdabd0e2057bba9dc05df51765b83559e9df7798c389a9c23f13f15a22077c242b8d6f55822ba8c24f1aefc864490f70f503f709d2d980b9bc18fece4187152a1d9ca5fab6b290953441b1c53f63f98863aae75bd8ea32996ab07976e498bad111d535252
Intrusion sets (APT) (1)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 00:13 · Modified 21/12/2025 00:13
Techniques (MITRE) (17)
-
Masquerading
-
Encrypted Channel
-
Phishing
-
Proxy
-
Data Encoding
-
Subvert Trust Controls
-
User Execution
-
Protocol Tunneling
-
Obfuscated Files or Information
-
Ingress Tool Transfer
-
Non-Application Layer Protocol
-
Remote Access Tools
-
Command and Scripting Interpreter
-
Web Service
-
Remote Services
-
Application Layer Protocol
-
Deobfuscate/Decode Files or Information
Malware (16)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 19:09 · Modified 21/12/2025 19:09
-
FamilyPublished 08/06/2026 10:30 · Modified 08/06/2026 10:30
-
FamilyPublished 28/11/2025 08:31 · Modified 28/11/2025 08:31
-
FamilyPublished 08/06/2026 10:30 · Modified 08/06/2026 10:30
-
FamilyPublished 28/11/2025 08:31 · Modified 28/11/2025 08:31
-
FamilyPublished 28/11/2025 08:31 · Modified 28/11/2025 08:31
-
FamilyPublished 28/11/2025 08:31 · Modified 28/11/2025 08:31
-
FamilyPublished 28/11/2025 08:31 · Modified 28/11/2025 08:31
-
FamilyPublished 28/11/2025 08:31 · Modified 28/11/2025 08:31
-
FamilyPublished 28/11/2025 08:31 · Modified 28/11/2025 08:31
-
Published 28/11/2025 08:31 · Modified 28/11/2025 08:31
-
FamilyPublished 28/11/2025 08:31 · Modified 28/11/2025 08:31
-
Published 28/11/2025 08:31 · Modified 28/11/2025 08:31
-
Published 28/11/2025 08:31 · Modified 28/11/2025 08:31
-
FamilyPublished 17/03/2026 11:03 · Modified 17/03/2026 11:03
-
Published 28/11/2025 08:31 · Modified 28/11/2025 08:31
Others (6)
- Tajikistan
- Uzbekistan
- Russian Federation
- Turkmenistan
- Kyrgyzstan
- Government and administrations