MeltingClaw is a downloader associated with the RomCom intrusion ecosystem and linked to the Russia-aligned activity cluster tracked as RomCom, Storm-0978, Void Rabisu, UNC2596, Tropical Scorpius, and TA829. First identified in 2024, it has been used in targeted intrusion chains against organizations of geopolitical interest, particularly in Ukraine, and has also appeared in broader RomCom campaigns affecting sectors including finance, manufacturing, defense, and logistics.
MeltingClaw functions as an intermediate payload-delivery component. It is commonly delivered through advanced spearphishing operations, including resume- and complaint-themed lures, and has also appeared in chains involving the Rust-based downloader RustyClaw. In observed campaigns, RustyClaw or related loaders execute MeltingClaw in the same process space, after which MeltingClaw retrieves and installs follow-on malware modules. Reported downstream payloads include the DustyHammock, ShadyHammock, and SingleCamper backdoors, which provide persistent access and support espionage-oriented post-compromise activity.
Operationally, MeltingClaw is part of a layered toolchain used to deepen access after initial compromise. Its role is to fetch and execute additional malicious components from attacker-controlled infrastructure, enabling operators to transition from delivery to long-term access. Through the backdoors it deploys, campaigns involving MeltingClaw have supported reconnaissance, arbitrary command execution, file delivery, and data theft. The malware has been tied to espionage and sabotage activity during the period following Russia’s invasion of Ukraine, reflecting RomCom’s overlap between cybercrime tradecraft and state-aligned targeting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A WinRAR zero-day vulnerability was exploited in the wild by the Russia-linked RomCom threat group... The high-severity WinRAR flaw tracked as CVE-2025-8088 has a CVSS score of 8.4 and enables attackers to misuse alternate data streams (ADSs) to achieve path traversal on Windows.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Advanced spear-phishing campaigns have been used to deliver the downloaders MeltingClaw and its cousin RustyClaw. These then download and install the backdoors DustyHammock or ShadyHammock.
Advanced spear-phishing campaigns have been used to deliver the downloaders MeltingClaw and its cousin RustyClaw. These then download and install the backdoors DustyHammock or ShadyHammock.
TA829's intrusions resulted in the deployment of the MeltingClaw or RustyClaw downloaders that deliver the ShadyHammock, DustyHammock, and SingleCamper backdoors.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MeltingClaw is a downloader malware attributed to RomCom, used as a secondary stage in infection chains to facilitate further payload delivery.
MeltingClaw is a downloader malware attributed to RomCom, used as a secondary stage in infection chains to facilitate further payload delivery.
A RomCom-associated downloader retrieved as a follow-on payload by RustyClaw.
MeltingClaw is a downloader malware linked to RomCom, used as a secondary payload in attack chains involving RustyClaw.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.