Nomadic Octopus

Nomadic Octopus is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments, diplomatic missions, and individuals, since at least 2014. Nomadic Octopus has been observed conducting campaigns involving Android and Windows malware, mainly using the Delphi programming language, and building custom variants.[1][2][3]

ID: G0133
Associated Groups: DustSquad
Version: 1.0
Created: 24 August 2021
Last Modified: 02 September 2022

Associated Group Descriptions

Name Description
DustSquad

[1][2][4]

Techniques Used

Domain ID Name Use
Enterprise T1036 伪装

Nomadic Octopus attempted to make Octopus appear as a Telegram Messenger with a Russian interface.[2]

Enterprise T1059 .001 命令与脚本解释器: PowerShell

Nomadic Octopus has used PowerShell for execution.[3]

.003 命令与脚本解释器: Windows Command Shell

Nomadic Octopus used cmd.exe /c within a malicious macro.[3]

Enterprise T1204 .002 用户执行: Malicious File

Nomadic Octopus as attempted to lure victims into clicking on malicious attachments within spearphishing emails.[2][3]

Enterprise T1105 输入工具传输

Nomadic Octopus has used malicious macros to download additional files to the victim's machine.[3]

Enterprise T1566 .001 钓鱼: Spearphishing Attachment

Nomadic Octopus has targeted victims with spearphishing emails containing malicious attachments.[1][3]

Enterprise T1564 .003 隐藏伪装: Hidden Window

Nomadic Octopus executed PowerShell in a hidden window.[3]

Software

References