Kaspersky security researchers have discovered a new backdoor that was likely developed by the Nobelium hacking group, which was behind last year’s SolarWinds supply chain attack . The backdoor Kaspersky discovered is called Tomiris and was first detected in June, although the first samples were deployed in February 2021.

Kaspersky researchers discovered Tomiris while investigating DNS hijacking attacks against multiple government services of a member state of the Commonwealth of Independent States.
See also: Microsoft: New FoggyWeb malware is a backdoor for hackers
“These attacks were relatively short and primarily targeted the mail servers of the affected organizations,” Kaspersky commented. “We do not know how the threat actor was able to achieve this, but we believe that it somehow obtained credentials to the registrar control panel used by the victims.”
Researchers say that cybercriminals directed victims to a fake domain, then tricked them into downloading a malicious software update. This update contained the Tomiris backdoor.
"Further analysis showed that the main purpose of the backdoor was to establish a foothold on the target system and download other malicious components," Kaspersky added.
Another variant can collect and steal documents from compromised systems.
Kaspersky assumes that the new backdoor has been created by the Nobelium group, as it has many similarities to Sunshuttle , which has been previously linked to the group (e.g., both developed in Go, have the same encoding scheme for C2 comms, etc.).
They also detected the Kazuar backdoor, which shares characteristics with the Sunburst malware (used in the SolarWinds attack) on the same network as Tomiris.
See also: SolarWinds Sunburst backdoor: Common elements with Russian APT group malware

However, researchers have not yet confirmed that the new Tomiris backdoor is linked to the Russian hacking group Nobelium. The malware may have been designed to mislead researchers.
“A very likely (but unconfirmed) hypothesis is that the creators of Sunshuttle began developing Tomiris around December 2020, when the SolarWinds attack was discovered, to replace their tools“.
Nobelium group
The Nobelium group, behind the attack on SolarWinds, affecting multiple US organizations and agencies, is the hacking arm of the Russian Foreign Intelligence Service (SVR), also tracked as APT29, The Dukes, or Cozy Bear.
See also: UK, Canada, EU and NATO blame Russia for SolarWinds hack
In April 2021, the United States government officially accused the SVR department of coordinating the attack on SolarWinds.
The cybersecurity company Volexity also linked the attack to the specific group, based on the tactics that were used in previous attacks.
Source: Bleeping Computer
