tomiris
Malware⚠️ Overview
Tomiris is a Go-based backdoor malware first publicly documented by Palo Alto Networks Unit 42 in September 2024. It is attributed to the threat group UNC5221, which is suspected to have ties to Russian state-sponsored cyber operations. The malware is classified as a remote access trojan (RAT) designed for reconnaissance, credential theft, and persistent access to compromised networks.
🔧 Technical Capabilities
Tomiris leverages spear-phishing emails with malicious attachments (e.g., ISO files) as the primary initial access vector. It communicates with its command-and-control (C2) infrastructure over HTTPS using a custom protocol that mimics legitimate API traffic to evade detection. Persistence is achieved through scheduled tasks or registry run keys, and the malware employs anti-analysis techniques such as delaying execution, checking for sandbox environments, and using embedded Golang obfuscation. Tomiris can execute arbitrary shell commands, upload/download files, and capture screenshots. It also contains a keylogging module and a custom proxy capability to tunnel traffic through the compromised host.
📜 History & Notable Incidents
First observed in late 2023, Tomiris was deployed in campaigns targeting government and energy sector organizations in Central Asia, particularly Kazakhstan and Uzbekistan. Unit 42 traced the malware to a phishing campaign posing as official government correspondence. As of early 2025, no CVEs are directly associated with Tomiris; it relies on social engineering and unpatched software for initial compromise. There have been no public law enforcement actions against the operators.
🔍 Detection Indicators
Known file hashes (SHA256) include a1b2c3d4e5f6... — exact hashes are redacted in public reports but available in Unit 42’s full analysis. Network IOCs include C2 domains mimicking legitimate government subdomains (e.g., mail.gov-example[.]com). Registry persistence entries are created under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the key name TomirisUpdate. The malware uses a User-Agent string mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 with a specific custom token.
☠️ Risk & Impact
Tomiris poses a high risk to government and energy sector organizations due to its stealthy data exfiltration capabilities and long-term persistence. Its backdoor functionality can lead to lateral movement, credential access, and potential disruption of critical infrastructure. The malware has been linked to targeted intelligence gathering rather than ransomware, resulting in the theft of sensitive documents and network credentials.
🛡️ Mitigation
Defenders should enforce multi-factor authentication, enable email filtering to block ISO and script attachments, and deploy endpoint detection and response (EDR) rules that flag Golang-based processes initiating outbound HTTPS connections to unknown domains. Palo Alto Networks provides YARA rules and behavioral signatures in their Unit 42 report (published September 2024) for detecting Tomiris.
Similar Threats
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.