Storm-0473
MISP
Tipo:
Unknown
Unknown
Paese:
KZ
KZ
Prima attivita:
Unknown
Unknown
Dettagli:
Storm-0473 (Tomiris) is a threat actor that has been active since at least 2019. They primarily target government and diplomatic entities in the Commonwealth of Independent States region, with occasional victims in other regions being foreign representations of CIS countries. Tomiris uses a wide variety of malware implants, including downloaders, backdoors, and file stealers, developed in different programming languages. They employ various attack vectors such as spear-phishing, DNS hijacking, and exploitation of vulnerabilities. There are potential ties between Tomiris and Turla, but they are considered separate threat actors with distinct targeting and tradecraft by Kaspersky.
Alias (107)
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
UNC2849
Metadata
| ID: | 618 |
| Created: | 13/01/2026 17:48 |
| Updated: | 08/03/2026 04:00 |