Skip to content
Cyberattack on US Real Estate Firm Utilizes Tuoni C2 Framework

Cyberattack on US Real Estate Firm Utilizes Tuoni C2 Framework

First seen 2 Dec 2025, 18:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

In October 2025, a cyberattack targeting a major U.S. real estate firm was attempted using the Tuoni command-and-control framework. The attack involved social engineering tactics, including impersonation of Microsoft Teams contacts, to execute a malicious PowerShell script. Morphisec reported that the threat actors employed advanced techniques such as steganography and AI-assisted delivery methods.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Tuoni in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed