Threats Tagged 'tuoni'
View all threats tagged with 'tuoni'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'tuoni'
Click on any threat for detailed analysis and mitigation recommendations
The ForumTroll APT group has launched a new targeted phishing campaign against Russian political scientists, exploiting plagiarism reports as bait. The attackers used sophisticated techniques, including a well-prepared domain and personalized emails, to deliver the Tuoni framework malware. This campaign follows their spring attacks, which targeted organizations using zero-day vulnerabilities. The fall campaign relied on social engineering, using emails posing as a scientific library to trick victims into downloading malicious archives. The final payload was delivered through a PowerShell script and established persistence using COM Hijacking. Despite being less technically sophisticated than the spring campaign, this operation demonstrates the group's continued focus on Russian and Belarusian targets. Join the discussion | AlienVault OTX General | 12/17/2025, 12:52:27 UTC Added: 12/17/2025, 22:15:21 UTC |
In October 2025, a major U. S.real estate firm was targeted by a sophisticated cyberattack leveraging the emerging Tuoni command-and-control (C2) framework. The attack chain began with social engineering via Microsoft Teams impersonation, delivering a malicious PowerShell script that used steganography to hide payloads within images and employed in-memory execution to evade detection. The Tuoni C2 framework served as the core implant, enabling stealthy remote control. The attack showed signs of AI-assisted code generation, indicating advanced threat actor capabilities. Morphisec's Automated Moving Target Defense (AMTD) technology successfully prevented the attack before execution, demonstrating effectiveness against unknown threats without relying on signatures or heuristics. Although the attack was neutralized, the techniques used highlight evolving adversary tactics that could threaten organizations globally. No known exploits are currently in the wild, and no CVE or specific threat actor attribution is available. The medium severity rating reflects the attack's complexity and potential impact if successful. Join the discussion | AlienVault OTX General | 11/19/2025, 08:52:05 UTC Added: 11/19/2025, 09:17:04 UTC |
Showing 1 to 2 of 2 results