Nomadic Octopus specifically targets Tajikistan officials and telecommunications services, says report

A report, released PRODAFT on April 27 this year, explores an operational environment which is owned by Nomadic Octopus espionage group that has reportedly been active since 2020.   “Nomadic Octopus’ Paperbug Campaign”, in particular, notes that the group specifically targets Tajikistan’s high ranking government officials, telecommunication services, and public service infrastructures.   The report says that […]

Asia-Plus

A report, released PRODAFT on April 27 this year, explores an operational environment which is owned by Nomadic Octopus espionage group that has reportedly been active since 2020.  

“Nomadic Octopus’ Paperbug Campaign”, in particular, notes that the group specifically targets Tajikistan’s high ranking government officials, telecommunication services, and public service infrastructures.  

The report says that according to unearthed victim data, Tajikistan is the ultimate target of this operation.  The target list includes but is not limited to Tajikistan’s government officials, public service infrastructures and the telecom provider.  

According to the frequency of screenshots being taken by Nomadic Octopus especially while targeted victims were writing e-mails and creating new contracts of their customers, the group spied on devices and took their notes diligently.

Operation PaperBug aligns with the common trend of attacking into Central Asia government infrastructure that recently became more prominent.  This trend reportedly can also be seen in other Russian speaking state-sponsored threat actors like Sofacy.  They have also been observed attacking telecommunication infrastructure in the Central Asian region, including Tajikistan.  This indicates that there might be some ties between the main subject of this report Nomadic Octopus and other prominent espionage groups like Sofacy

The report has published names of some high-ranking Tajik state officials who might have been the victims of a hacker attack.  Among them are the then Minister of Transport Khudoyor Khduoyorzoda, the former Deputy Governor of Khatlon Province (currently Deputy Mayor of Dushanbe) Amirkhon Qurbonzoda, deputy Interior Minister Saidnakhsha Rahmonzoda, Head of the CIS Department at President’s Executive Office Andulaziz Sharifi, former Head of the Department for Agricultrue and Environmental Protection at President’s Executive Office (currently Head of Fayzobod District) Bobisho Kholzoda.  

The Group interest reportedly also covers OT devices; there are four gas stations and one cash register.  The Group also targets telecom companies.  The aspect setting this operation apart from other operation conducted in Central Asia is the method it uses to compromise its victims. The starting point of this operation is the compromisation of the networks of a Tajikistan based telecom company, according to the report.  

Virus Bulletin says Nomadic Octopus is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments, diplomatic missions, and individuals, since at least 2015. Nomadic Octopus is a new APT (advanced persistent threat), which has been observed conducting campaigns involving Android and Windows malware, mainly using the Delphi programming language, and building custom variants.  According to Virus Bulletin, the group has been active since at least 2015.  The main goal of Nomadic Octopus appears to be cyber espionage against high-value targets, including diplomatic missions in the region.  However, besides these high-value targets, it reportedly also targets a local political blogger, which may suggest that Nomadic Octopus also conducts cyber surveillance operations.  Nomadic Octopus performs its activity using unique, custom-made malware. 

PRODAFT is a pioneering company in the cyber threat intelligence industry, supporting private and public sectors globally with its solutions.  With a mission of preventing breaches before they happen, PRODAFT reduces the time and energy spent on analysis, interpretation, and verification of potential threats.  Every day, hundreds of companies from critical sectors use U.S.T.A. SaaS platform to receive actionable insights right from the source.  Its mission is reportedly to protect citizens, businesses, and governments from major security threats by providing timely and accurate information. PRODAFT was named one of Europe’s most successful technology initiatives by the Red Herring international media agency.

Join us on social media!

Article translations:

Related Article

Оби зулол
Оби зулол

Most Read

Акика Алиф

Recent Articles

Donald Trump arrives in Beijing

Trump will spend three days in China.

In Tajikistan, a unique surgery was performed for the first time on a child with an extremely rare pathology

Tajik and Russian surgeons successfully performed the most complex reconstruction of the bladder and abdominal wall for a child with recurrent exstrophy.

The ministry of health states that hantavirus does not threaten Tajikistan

Cases of infection with this virus were detected on board the cruise liner Hondius near the Canary Islands.

Tajikistan lags behind other Central Asian countries in number of chain hotels – study

The Republic remains a niche market with a limited number of quality hotels.

Climate risks threaten food security in Central Asia – FAO

Land degradation reduces agricultural productivity. The loss of biodiversity weakens the ecosystems that farmers, livestock breeders, and rural communities depend on.

Potential or illusion? Why the world overlooks Tajikistan’s mineral wealth

The republic may indeed possess significant reserves of rare metals, but there is a catch...

The case of ousted Kyrgyz security boss classified and moves to court

The former head of the GKNB is charged with violent seizure of power and abuse of official position.

Trump states that Iran’s nuclear program is a higher priority than U.S. citizens’ economic issues

Fluctuations in energy prices led to record inflation in the United States in April, the highest in the past three years.

Foot-and-mouth disease, plague, and flu: Central Asia threatened by transboundary animal diseases

FAO urges Central Asian countries to strengthen coordination and epidemiological surveillance.

Tajikistan approves the second phase of the Electric Transport Development Program; $95 million will be allocated for its implementation.

At this stage, the authorities are focusing on charging infrastructure, services for electric vehicles, and the expansion of the electric bus fleet.