216.73.217.22

Sophisticated Tuoni C2 Attack on U.S. Real Estate Firm Thwarted

· Published 19/11/2025 08:52 · Modified 19/11/2025 09:48

Export JSON

Essential information

Published
19/11/2025 08:52
Modified
19/11/2025 09:48
Tags
2025-11-19 ai-assisted amtd in-memory execution powershell prevention real estate steganography tuoni tuoni c2
Related entities
4 observables, 11 techniques (mitre), 1 malware, 2 others

Description

In October 2025, a major U.S. company was targeted by a highly advanced cyberattack using the emerging framework. The attack, which showed signs of AI assistance in code generation, was neutralized by Morphisec's Automated Moving Target Defense () technology. The campaign likely began with social engineering via Microsoft Teams impersonation, followed by a malicious script. The attack chain involved to hide payloads in images and techniques to evade detection. The framework, a sophisticated command-and-control tool, was used as the core implant. Morphisec's -first approach successfully blocked the attack before execution, highlighting the effectiveness of against unknown threats without relying on signatures or behavioral heuristics.

External references