Tomiris

S0671

Malware.View on attack.mitre.org

About this malware

Tomiris is a backdoor written in Go that continuously queries its C2 server for executables to download and execute on a victim system. It was first reported in September 2021 during an investigation of a successful DNS hijacking campaign against a Commonwealth of Independent States (CIS) member. Security researchers assess there are similarities between Tomiris and GoldMax.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1005
Data from Local System

Tomiris has the ability to collect recent files matching a hardcoded list of extensions prior to exfiltration.

T1027.002
Software Packing

Tomiris has been packed with UPX.

T1041
Exfiltration Over C2 Channel

Tomiris can upload files matching a hardcoded set of extensions, such as .doc, .docx, .pdf, and .rar, to its C2 server.

T1053.005
Scheduled Task

Tomiris has used `SCHTASKS /CREATE /SC DAILY /TN StartDVL /TR "[path to self]" /ST 10:00` to establish persistence.

T1071.001
Web Protocols

Tomiris can use HTTP to establish C2 communications.

T1105
Ingress Tool Transfer

Tomiris can download files and execute them on a victim's system.

T1497.003
Time Based Checks

Tomiris has the ability to sleep for at least nine minutes to evade sandbox-based analysis systems.

T1568
Dynamic Resolution

Tomiris has connected to a signalization server that provides a URL and port, and then Tomiris sends a GET request to that URL to establish C2.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Kaspersky Tomiris Sep 2021 Open source
    Kwiatkoswki, I. and Delcher, P. (2021, September 29). DarkHalo After SolarWinds: the Tomiris connection. Retrieved December 27, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.