SnipBot is a Windows remote access trojan and backdoor associated with the Russia-aligned RomCom threat group. Also known as NESTPACKER and designated RomCom 5.0, it incorporates functionality from earlier RomCom versions, including PEAPOD. Samples date to at least December 2023, and the malware is used in cyberespionage and data-collection operations.
SnipBot uses a multistage infection chain, typically beginning with a code-signed executable downloader followed by additional executable or DLL payloads. Email links deliver downloaders disguised as documents, sometimes through redirect chains and legitimate file-sharing services. Earlier delivery activity also used a document claiming that a missing font package required installation, directing victims to an Adobe-themed landing page. In July 2025, RomCom used malicious résumé-themed RAR attachments exploiting the WinRAR path traversal vulnerability CVE-2025-8088 to attempt deployment of a SnipBot variant against financial, manufacturing, defense, and logistics organizations in Europe and Canada. That variant used a modified PuTTY CAC executable to decrypt and execute shellcode.
The main backdoor supports 27 commands, including remote command execution, drive and directory enumeration, process listing, file upload and download, targeted document exfiltration, and retrieval and execution of additional payloads. Auxiliary tools support SOCKS proxying and SSH tunneling. SnipBot collects host and domain information, stores encrypted payloads in the Windows registry, and uses COM hijacking for persistence and payload execution within Windows Explorer. Its evasion techniques include encrypted strings, dynamically resolved API functions, window message-based control-flow obfuscation, and anti-sandbox checks based on executable identity and evidence of prior user activity. Observed operator activity has included internal network discovery, archive-based data staging, and attempted exfiltration using legitimate administration and file-transfer tools.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Successful exploitation attempts delivered various backdoors used by the RomCom group, specifically a SnipBot variant, RustyClaw, and the Mythic agent. | ESET researchers have discovered a previously unknown zero-day vulnerability in WinRAR being exploited in the wild by Russia-aligned group RomCom... now assigned CVE-2025-8088: a path traversal vulnerability, made possible with the use of alternate data streams.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Further evolution led to the discovery of ‘SnipBot’ (considered RomCom 5.0), with samples identified dating back to December 2023 and analysed in 2024.”
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The backdoor used by the group is capable of executing commands and downloading additional modules to the victim’s machine.
"SnipBot... enabling command execution and data exfiltration"
ESET researchers have discovered a previously unknown zero-day vulnerability in WinRAR being exploited in the wild by Russia-aligned group RomCom... The vulnerability, CVE-2025-8088, is a path traversal vulnerability... Disguised as an application document, the weaponized archives exploited a path traversal flow to compromise its targets.
Creates and manages registry keys ( HKCU\SOFTWARE\AppDataSoft\Software ) to store encrypted payloads and keep track of updates.
Post-Infection Activity: Downloads additional DLL payloads, injecting them into explorer.exe using COM hijacking.
It also employs window message-based control flow obfuscation.
Encrypts strings, including the C2 domain and API function names, to evade detection.
Post-Infection Activity: Downloads additional DLL payloads, injecting them into explorer.exe using COM hijacking.
It deploys an initial signed executable downloader, followed by unsigned EXEs or DLLs.
Command & Control: Contacts its C2 domains (e.g., xeontime[.]com ) to download payloads.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware variant delivered via WinRAR CVE-2025-8088 exploitation for initial access and persistence (via Windows Startup folder).
Backdoor used for long-term persistence and covert reconnaissance, described as deployed by RomCom after exploitation of a WinRAR path traversal zero-day.
You can also test your defenses against hundreds of other malware variants, such as SnipBot, SlipScreen Loader, RustyClaw, within minutes...
A stealth-focused remote access trojan/backdoor used for long-term control and espionage. Uses advanced control-flow obfuscation, is delivered via multi-stage loaders, communicates with C2 over HTTPS, supports command execution and modular payload delivery, and performs host reconnaissance prior to further hands-on activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.