Threat group.View on attack.mitre.org
Nomadic Octopus is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments, diplomatic missions, and individuals, since at least 2014. Nomadic Octopus has been observed conducting campaigns involving Android and Windows malware, mainly using the Delphi programming language, and building custom variants.
| Technique | Procedure example |
|---|---|
| T1036 Masquerading |
Nomadic Octopus attempted to make Octopus appear as a Telegram Messenger with a Russian interface. |
| T1059.001 PowerShell |
Nomadic Octopus has used PowerShell for execution. |
| T1059.003 Windows Command Shell |
Nomadic Octopus used |
| T1105 Ingress Tool Transfer |
Nomadic Octopus has used malicious macros to download additional files to the victim's machine. |
| T1204.002 Malicious File |
Nomadic Octopus as attempted to lure victims into clicking on malicious attachments within spearphishing emails. |
| T1564.003 Hidden Window |
Nomadic Octopus executed PowerShell in a hidden window. |
| T1566.001 Spearphishing Attachment |
Nomadic Octopus has targeted victims with spearphishing emails containing malicious attachments. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.