Storm-0473 is a cyber threat actor targeting government and diplomatic entities in the CIS region since at least 2019.
Analyst brief
Storm-0473 (UNC2849/Tomiris) is a cyber threat actor active since at least 2019. It primarily targets government and diplomatic entities in the CIS region, occasionally also targeting their foreign representations. Their TTPs include spear-phishing, DNS hijacking, and exploitation of vulnerabilities, using a variety of malware such as downloaders, backdoors, and file stealers written in different programming languages. Defenders should focus on network segmentation, DNS monitoring, targeted anti-phishing training, and detecting multi-stage malware delivery.
Storm-0473
UNC2849
unknown
Storm-0473 (Tomiris) is a threat actor that has been active since at least 2019. They primarily target government and diplomatic entities in the Commonwealth of Independent States region, with occasional victims in other regions being foreign representations of CIS countries. Tomiris uses a wide variety of malware implants, including downloaders, backdoors, and file stealers, developed in different programming languages. They employ various attack vectors such as spear-phishing, DNS hijacking, and exploitation of vulnerabilities. There are potential ties between Tomiris and Turla, but they are considered separate threat actors with distinct targeting and tradecraft by Kaspersky.
Which sectors does Storm-0473 (UNC2849) primarily target?+
It primarily targets government and diplomatic entities in the CIS region, occasionally also targeting their foreign representations.
What key tactics should defenders focus on regarding Storm-0473?+
Storm-0473 employs various attack vectors such as spear-phishing, DNS hijacking, and exploitation of vulnerabilities, using a variety of malware such as downloaders, backdoors, and file stealers written in different programming languages. Defenders should focus on network segmentation, DNS monitoring, targeted anti-phishing training, and detecting multi-stage malware delivery.