Skip to main content

Threats Tagged 'tuoni'

View all threats tagged with 'tuoni'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: tuoni

Threats Tagged 'tuoni'

Click on any threat for detailed analysis and mitigation recommendations

The ForumTroll APT group has launched a new targeted phishing campaign against Russian political scientists, exploiting plagiarism reports as bait. The attackers used sophisticated techniques, including a well-prepared domain and personalized emails, to deliver the Tuoni framework malware. This campaign follows their spring attacks, which targeted organizations using zero-day vulnerabilities. The fall campaign relied on social engineering, using emails posing as a scientific library to trick victims into downloading malicious archives. The final payload was delivered through a PowerShell script and established persistence using COM Hijacking. Despite being less technically sophisticated than the spring campaign, this operation demonstrates the group's continued focus on Russian and Belarusian targets.

Join the discussion

In October 2025, a major U. S.real estate firm was targeted by a sophisticated cyberattack leveraging the emerging Tuoni command-and-control (C2) framework. The attack chain began with social engineering via Microsoft Teams impersonation, delivering a malicious PowerShell script that used steganography to hide payloads within images and employed in-memory execution to evade detection. The Tuoni C2 framework served as the core implant, enabling stealthy remote control. The attack showed signs of AI-assisted code generation, indicating advanced threat actor capabilities. Morphisec's Automated Moving Target Defense (AMTD) technology successfully prevented the attack before execution, demonstrating effectiveness against unknown threats without relying on signatures or heuristics. Although the attack was neutralized, the techniques used highlight evolving adversary tactics that could threaten organizations globally. No known exploits are currently in the wild, and no CVE or specific threat actor attribution is available. The medium severity rating reflects the attack's complexity and potential impact if successful.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: tuoni
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses