HomeSecurityAPT “Tomiris” uses Turla malware, confusing researchers

APT 'Tomiris' uses Turla malware, confusing researchers

Some campaigns previously linked to the Russian Advanced Persistent Threat (APT) Turla were actually run by an entirely separate group. Researchers have named this group “Tomiris.”.

Turla (also known as Snake, Venomous Bear, or Ourobouros) is a notorious threat actor with ties to the Russian government. Over the years, it has used zero-days, legitimate software, and other means to deploy backdoors into systems belonging to militaries and governments, diplomatic entities, and technology and research organizations. In one case, it was linked, through the Kazuar backdoor, to the SolarWinds breach.

However, it’s not all Turla. In a new paper, Kaspersky researchers have published evidence that some attacks previously associated with Turla were carried out by Tomiris – a completely different group with different tactics, techniques and procedures (TTPs) and connections.

“We strongly believe that Tomiris is unique,” ​​says Pierre Delcher, senior security researcher at Kaspersky’s GreAT. “It’s not the same targeting, not the same tools, not the same complexity as Turla.”

See also: Anonymous Sudan: Ben Gurion Airport and Israel Electric Corporation sites attacked

Tomiris

Separating Turla and Tomiris

Cyber ​​attribution is difficult. “Highly skilled hackers use techniques that disguise origins , make themselves anonymous, or even falsely attribute themselves to other threat groups to throw investigators off-track,” explains Adam Flatley, a former director of operations at the National Security Agency and vice president of intelligence at [Redacted]. “Often we can only rely on operational security to find clues to their true identity.”

Tomiris is a case in point. Kaspersky began tracking what now appears to have been Tomiris activity three years ago, in a DNS hijacking campaign against a Commonwealth of Independent States (CIS) government . The culprits’ characteristics appeared to be a mix of Russian APT soup. The Tomiris backdoor was discovered on networks alongside Turla’s Kazuar backdoor, which had been deployed alongside the Sunburst malware used in the SolarWinds breach .

See also: APC warns of critical RCE flaws in UPS software

However, the details linking Tomiris and Turla never quite meshed together. “The implants they developed were… well, they sounded dumb compared to what we knew about Turla,” Delcher says. “So really, there was essentially nothing in common , and even the goals didn’t fit with what we knew about Turla’s past interests .”

“Targeting is an important element,” Delcher explains. “Tomiris is very focused on government organizations in the CIS, including the Russian Federation, while in the cybersecurity scene, some vendors are linking Turla to a Russian-backed actor. This wouldn’t make much sense if a Russian-backed actor was targeting the Russian Federation.”

Just this year, Mandiant published research into a Turla campaign, in which it admitted, at one point, that there were “ some elements of this campaign that appear to deviate from historical Turla operations.” Kaspersky researchers have assigned these findings to the Tomiris operations, with “moderate confidence.”

Turla

Connecting Turla and Tomiris

All of this does not mean that there is absolutely no relationship between Tomiris and Turla.

In attacks between 2021 and 2023, Tomiris used KopiLuwak and TunnusSched – two of Turla’s malicious tools. Delcher says, “we strongly believe that they may have been working together at some point or may still be working together at this time.”

“Exactly how the groups are connected is up for debate,” Delcher continued. “They could run a joint operation or rely on a similar supply chain. For example, they could have asked an independent developer to develop a backdoor, and the independent developer provided it to both Turla and Tomiris.”

See also: KuCoin: Twitter account hacked to promote scam crypto giveaway

Why this matters for businesses

Distinguishing between threat actors can help organizations defend themselves more effectively, Delcher says.

For example, an organization that has been affected by Turla or is concerned about Turla might notice the Kazuar malware and assume it is the work of this group.

Diligent defenders would do well to pay attention to the subtle differences between groups, but certain principles apply to all APTs.

Source of information: darkreading.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS