Storm-0473Storm-0473

Also known as: Storm-0473 · UNC2849

Known aliases
2

Profile

Storm-0473 (Tomiris) is a threat actor that has been active since at least 2019. They primarily target government and diplomatic entities in the Commonwealth of Independent States region, with occasional victims in other regions being foreign representations of CIS countries. Tomiris uses a wide variety of malware implants, including downloaders, backdoors, and file stealers, developed in different programming languages. They employ various attack vectors such as spear-phishing, DNS hijacking, and exploitation of vulnerabilities. There are potential ties between Tomiris and Turla, but they are considered separate threat actors with distinct targeting and tradecraft by Kaspersky.

Aliases· 2

Storm-0473UNC2849

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Storm-2372
Software
Tomiris
Actor
Storm-0324
Actor
Storm-2077
Actor
UNC4393
Actor
Storm-0494
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.