Nomadic Octopus

MITRE ATT&CK: G0133 View on attack.mitre.org

Aliases: DustSquad, Nomadic Octopus

First seen
2014-01-01 00:00:00
Origin
RU
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:06:49

Targeted industries: government-and-public-sector

Targeted regions: country_code:kz country_code:uz country_code:kg country_code:tm country_code:tj

Context

Nomadic Octopus is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments, diplomatic missions, and individuals, since at least 2014. Nomadic Octopus has been observed conducting campaigns involving Android and Windows malware, mainly using the Delphi programming language, and building custom variants.

Detection coverage

  • 368 Sigma rules

Malware & tools used

  • Windows Command Shell (attack-pattern)
  • Masquerading (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Malicious File (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Hidden Window (attack-pattern)
  • PowerShell (attack-pattern)
  • Octopus (malware)

Reports & references

  • Kaspersky — 88200 (report)
  • prodaft.com — Paperbug Tlpwhite 1 (report)
  • virusbulletin.com — Nomadic Octopus Cyber Espionage Central Asia (report)
  • MITRE ATT&CK — G0133 (report)
  • securityaffairs.co — Russia Linked Apt Dustsquad (report)
  • securityweek.com — Russia Linked Hackers Target Diplomatic Entities Central Asia (report)
  • virusbulletin.com — Cherepanov Vb2018 Octopus (report)

External references