HomeSecurityTomiris: The new backdoor that can be linked to hackers...

Tomiris: The new backdoor that may be linked to SolarWinds hackers

Kaspersky security researchers have discovered a new backdoor that was likely developed by the Nobelium hacking group, which was behind last year’s SolarWinds supply chain attack . The backdoor Kaspersky discovered is called Tomiris and was first detected in June, although the first samples were deployed in February 2021.

Tomiris backdoor Nobelium

Kaspersky researchers discovered Tomiris while investigating DNS hijacking attacks against multiple government services of a member state of the Commonwealth of Independent States.

See also: Microsoft: New FoggyWeb malware is a backdoor for hackers

“These attacks were relatively short and primarily targeted the mail servers of the affected organizations,” Kaspersky commented. “We do not know how the threat actor was able to achieve this, but we believe that it somehow obtained credentials to the registrar control panel used by the victims.”

Researchers say that cybercriminals directed victims to a fake domain, then tricked them into downloading a malicious software update. This update contained the Tomiris backdoor.

"Further analysis showed that the main purpose of the backdoor was to establish a foothold on the target system and download other malicious components," Kaspersky added.

Another variant can collect and steal documents from compromised systems.

Kaspersky assumes that the new backdoor has been created by the Nobelium group, as it has many similarities to Sunshuttle , which has been previously linked to the group (e.g., both developed in Go, have the same encoding scheme for C2 comms, etc.).

They also detected the Kazuar backdoor, which shares characteristics with the Sunburst malware (used in the SolarWinds attack) on the same network as Tomiris.

See also: SolarWinds Sunburst backdoor: Common elements with Russian APT group malware

Solarwinds Nobelium

However, researchers have not yet confirmed that the new Tomiris backdoor is linked to the Russian hacking group Nobelium. The malware may have been designed to mislead researchers.

“A very likely (but unconfirmed) hypothesis is that the creators of Sunshuttle began developing Tomiris around December 2020, when the SolarWinds attack was discovered, to replace their tools“.

Nobelium group

The Nobelium group, behind the attack on SolarWinds, affecting multiple US organizations and agencies, is the hacking arm of the Russian Foreign Intelligence Service (SVR), also tracked as APT29, The Dukes, or Cozy Bear.

See also: UK, Canada, EU and NATO blame Russia for SolarWinds hack

In April 2021, the United States government officially accused the SVR department of coordinating the attack on SolarWinds.

The cybersecurity company Volexity also linked the attack to the specific group, based on the tactics that were used in previous attacks.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS