RomCom is a Russia-aligned threat actor tracked under aliases including Storm-0978, Void Rabisu, CIGAR, Tropical Scorpius, UNC2596, UNC4895, Underground Team, and in some reporting UAC-0180. The actor has conducted both financially motivated cybercrime and targeted espionage operations, with activity focused especially on Ukraine and European government and defense-related targets, while also targeting organizations in North America and selected business sectors such as finance, manufacturing, logistics, and telecommunications. Reporting links the group to Russian interests and, in some cases, likely support to Russian government objectives. RomCom is known for spear-phishing, trojanized software distribution, and exploitation of high-profile vulnerabilities for initial access. It has been observed exploiting CVE-2023-36884 in malicious Office-document campaigns against government and defense entities, and CVE-2025-8088 in WinRAR in highly targeted spear-phishing operations. It has also been tied to a Firefox-to-Windows exploit chain using CVE-2024-9680 and CVE-2024-49039. Campaign lures have referenced NATO, the Ukrainian World Congress, job applications, and other topical themes aligned to victim interests. The actor’s malware ecosystem includes ROMCOM RAT and later tooling such as SnipBot variants, RustyClaw, MeltingClaw, DustyHammock, ShadyHammock, TransferLoader, and Mythic Agent. ROMCOM RAT functions as a backdoor supporting command execution, file operations, process enumeration, reverse shell capability, and download of additional payloads. Associated tooling has supported long-term access, reconnaissance, stealthy payload delivery, and data theft. RomCom operations have also used phishing-delivered RAR archives, compromised or deceptive download channels, and in some cases services associated with initial access brokers such as SocGholish. RomCom has been associated with credential-gathering and intelligence collection as well as ransomware activity. Microsoft and other researchers have described the actor as conducting targeted credential theft in support of intelligence operations. Separate reporting connects aliases such as Tropical Scorpius to deployment of Cuba ransomware, including double-extortion operations, use of a leak site, reconnaissance, credential theft, privilege escalation, lateral movement, and security-tool disabling through custom or signed drivers. More recent assessments characterize the cluster as dual-motivated, combining financial objectives with espionage, but the most consistently supported strategic pattern is intelligence-driven targeting aligned with Russian geopolitical interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
30 malware families attributed to this actor across reporting.
25 additional families tracked in Mallory.
9 CVEs this actor has used in observed campaigns. 9 of them exploited in the wild.
In this blog post, I’ll be diving into the technical details of the WinRAR vulnerability, identified as CVE-2025-8088. This vulnerability carries a high severity score of 8.4 and affects WinRAR on Windows operating systems due to a path traversal flaw.
Microsoft Threat Intelligece has identified threat actors abusing a recently disclosed vulnerability, CVE-2023-36884, in phishing campaigns containing malicious Word documents against government entities in Europe and North America.
Two vulnerabilities (CVE-2024-9680 and CVE-2024-49039, detailed in the next section) were exploited as zero-days by CIGAR... it was later assigned CVE-2024-49039. ... The in-the-wild CVE-2024-49039 exploit ... could achieve both a sandbox escape and privilege escalation.
Tropical Scorpius has also been observed exploiting vulnerabilities in Microsoft Exchange Server, including ProxyShell and ProxyLogon.
Mandiant has also identified the exploitation of Microsoft Exchange vulnerabilities, including ProxyShell and ProxyLogon, as another access point leveraged by UNC2596 likely as early as August 2021.
4 more CVEs tied to this actor tracked in Mallory.
75 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as one of several Russian hacking groups known to have exploited the WinRAR vulnerability CVE-2025-8088.
Used SocGholish to deliver Mythic Agent, demonstrating use of SocGholish as an initial access broker service.
Russia-linked threat actor also reported as exploiting CVE-2025-8088.
Reported as one of the Russia-aligned threat actors that exploited CVE-2025-8088 earlier in the year.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.