ATT&CKGroupsNomadic Octopus

Nomadic Octopus

G0133

Threat group.View on attack.mitre.org

About this group

Nomadic Octopus is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments, diplomatic missions, and individuals, since at least 2014. Nomadic Octopus has been observed conducting campaigns involving Android and Windows malware, mainly using the Delphi programming language, and building custom variants.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1036
Masquerading

Nomadic Octopus attempted to make Octopus appear as a Telegram Messenger with a Russian interface.

T1059.001
PowerShell

Nomadic Octopus has used PowerShell for execution.

T1059.003
Windows Command Shell

Nomadic Octopus used cmd.exe /c within a malicious macro.

T1105
Ingress Tool Transfer

Nomadic Octopus has used malicious macros to download additional files to the victim's machine.

T1204.002
Malicious File

Nomadic Octopus as attempted to lure victims into clicking on malicious attachments within spearphishing emails.

T1564.003
Hidden Window

Nomadic Octopus executed PowerShell in a hidden window.

T1566.001
Spearphishing Attachment

Nomadic Octopus has targeted victims with spearphishing emails containing malicious attachments.

Software1

Campaigns0

None recorded.

References3

  1. ESET Nomadic Octopus 2018 Open source
    Cherepanov, A. (2018, October 4). Nomadic Octopus Cyber espionage in Central Asia. Retrieved October 13, 2021.
  2. Securelist Octopus Oct 2018 Open source
    Kaspersky Lab's Global Research & Analysis Team. (2018, October 15). Octopus-infested seas of Central Asia. Retrieved November 14, 2018.
  3. Security Affairs DustSquad Oct 2018 Open source
    Paganini, P. (2018, October 16). Russia-linked APT group DustSquad targets diplomatic entities in Central Asia. Retrieved August 24, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.