Nomadic Octopus
MITRE ATT&CK: G0133 View on attack.mitre.org
Aliases: DustSquad, Nomadic Octopus
- First seen
- 2014-01-01 00:00:00
- Origin
- RU
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:06:49
Targeted industries: government-and-public-sector
Targeted regions: country_code:kz country_code:uz country_code:kg country_code:tm country_code:tj
Context
Nomadic Octopus is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments, diplomatic missions, and individuals, since at least 2014. Nomadic Octopus has been observed conducting campaigns involving Android and Windows malware, mainly using the Delphi programming language, and building custom variants.
Detection coverage
- 368 Sigma rules
Malware & tools used
- Windows Command Shell (attack-pattern)
- Masquerading (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Malicious File (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Hidden Window (attack-pattern)
- PowerShell (attack-pattern)
- Octopus (malware)
Reports & references
- Kaspersky — 88200 (report)
- prodaft.com — Paperbug Tlpwhite 1 (report)
- virusbulletin.com — Nomadic Octopus Cyber Espionage Central Asia (report)
- MITRE ATT&CK — G0133 (report)
- securityaffairs.co — Russia Linked Apt Dustsquad (report)
- securityweek.com — Russia Linked Hackers Target Diplomatic Entities Central Asia (report)
- virusbulletin.com — Cherepanov Vb2018 Octopus (report)