Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 19:00:58 UTC Home > List all groups > List all tools > List all groups using tool Tunnus Tool: Tunnus Names Tunnus QUIETCANARY Kapushka Category Malware Type Backdoor Description (Kaspersky) A .NET-based backdoor with the ability to run commands or perform file actions on an infected system and send the results to its command-and-control servers. So far, the infrastructure has been built using compromised sites with vulnerable Wordpress installations. According to the company’s telemetry, Tunnus activity started in March and remained active. Information MITRE ATT&CK Malpedia Last change to this tool card: 27 August 2024 Download this tool card in JSON format All groups using tool Tunnus Changed Name Country Observed APT groups   Tomiris [Unknown] 2020     Turla, Waterbug, Venomous Bear 1996-2024   https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ab2cec4c-4871-4495-8dc5-eb129e7516a3 Page 1 of 2 2 groups listed (2 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ab2cec4c-4871-4495-8dc5-eb129e7516a3 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ab2cec4c-4871-4495-8dc5-eb129e7516a3 Page 2 of 2