Malware likely designed and developed by the Nobelium advanced persistent threat (APT) behind last year’s SolarWinds supply chain attack. Moscow-based firm Kaspersky codenamed the malware “Tomiris,” calling out its similarities to another second-stage malware used during the campaign, SUNSHUTTLE. Tomiris is written in Go and deployed via a successful DNS hijacking attack during which targets attempting to access the login page of a corporate email service were redirected to a fraudulent domain set up with a lookalike interface.”]
Source: https://thehackernews.com/2021/09/new-tomiris-backdoor-found-linked-to.html

