RomCom is a Russia-based threat actor active since at least 2022 that conducts espionage, credential theft, ransomware, and extortion operations. It is also tracked as Storm-0978, Void Rabisu, Tropical Scorpius, UNC2596, UAC-0180, CIGAR, and UNC4895, although vendor tracking scopes can differ. Its espionage targeting aligns with Russian interests, particularly against Ukraine and its allies. Targets include Ukrainian government, defense, and energy organizations, European government bodies, US pharmaceutical and insurance organizations, Germany's legal sector, and information technology companies, food brokers, and manufacturers. The actor uses spear-phishing, geopolitical lures, impersonated software websites, and trojanized installers to deliver the RomCom remote-access backdoor. Its tooling includes evolved backdoor variants such as PEAPOD and SnipBot, supporting remote command execution, host and process enumeration, file transfer, and targeted data exfiltration. Observed techniques include signed downloaders, obfuscation, anti-sandbox checks, scheduled-task persistence, and COM hijacking. RomCom exploited CVE-2023-36884 through malicious Office documents in 2023, chained Firefox vulnerability CVE-2024-9680 with Windows vulnerability CVE-2024-49039 for browser compromise, sandbox escape, and SYSTEM-level execution in 2024, and exploited WinRAR path traversal vulnerability CVE-2025-8088 through phishing-delivered archives in 2025. Financially motivated operations have included deployment of Cuba and Underground ransomware. Tropical Scorpius activity includes reconnaissance, credential harvesting with Mimikatz and KerberCache, Kerberoasting, exploitation of Windows and Exchange vulnerabilities, lateral movement, and use of a kernel driver to terminate security products. Cuba operations use double extortion and a leak site. Underground encrypts victim files, deletes shadow copies, terminates processes that impede encryption, and clears Windows event logs.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
61 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
31 malware families attributed to this actor across reporting.
26 additional families tracked in Mallory.
9 CVEs this actor has used in observed campaigns. 9 of them exploited in the wild.
RARLAB WinRAR 7.13 이전 버전에서 발견된 Path Traversal 취약점으로, 공격자는 순회 문자인 “..\” 와 Alternate Data Stream(ADS)를 활용해 경로 검증을 우회하고, 압축 해제 시 임의 경로에 파일을 생성할 수 있다.
This campaign used a zero-day vulnerability tracked as CVE-2023-36884, a remote code execution vulnerability in windows search files that is exploited via crafted Office Open eXtensible Markup Language (OOXML) documents.
Their exploitation of CVE-2024-49039 through Task Scheduler's overly permissive SDDL (D:P(A;;GA;;;S-1-15-2-1)(A;;GA;;;WD)) showcases how adversaries continue to find new ways to abuse Windows permissions. While this particular vulnerability has been patched, it’s important to monitor SDDL changes across your environment.
Later, in October-November 2024, RomCom executed a sophisticated zero-click attack campaign by chaining two zero-day vulnerabilities: CVE-2024-9680 (a critical use-after-free flaw in Mozilla Firefox's animation component) and CVE-2024-49039 (a Windows privilege escalation flaw allowing escape from the Firefox sandbox).
Tropical Scorpius has also been observed exploiting vulnerabilities in Microsoft Exchange Server, including ProxyShell and ProxyLogon.
4 more CVEs tied to this actor tracked in Mallory.
136 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a phishing campaign against government entities in Europe and North America using Ukraine World Congress and NATO-themed document lures. Malicious Office documents exploited CVE-2023-36884 through embedded RTF objects and chained external-content retrievals, ultimately downloading a payload and enabling remote code execution.
Referenced as the likely related intrusion set whose historic campaigns overlap with SHADOW-VOID-042 in infrastructure, lures, and TTPs; described as an actor with both financial and espionage motivations aligned with Russian interests.
Referenced as one of several Russian hacking groups known to have exploited the WinRAR vulnerability CVE-2025-8088.
Used SocGholish to deliver Mythic Agent, demonstrating use of SocGholish as an initial access broker service.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.