RomCom is a Windows remote access trojan and backdoor family associated with the Russia-aligned threat actor commonly tracked as Storm-0978, UNC2596, Tropical Scorpius, and Void Rabisu. Initially linked to cybercriminal activity and ransomware operations, it has evolved into a dual-use intrusion platform employed for both financially motivated attacks and espionage-oriented campaigns, particularly against organizations connected to Ukraine and targets in Europe and North America.
RomCom has been delivered through multiple intrusion vectors. Documented delivery methods include spearphishing emails carrying malicious Office documents, exploitation of CVE-2023-36884 to deliver backdoors via crafted Word files, and exploitation of the WinRAR path traversal vulnerability CVE-2025-8088 through weaponized archive attachments. Operators have also distributed RomCom through trojanized installers masquerading as legitimate software, fake browser or software update chains such as SocGholish, and malvertising-driven exploitation chains. Campaign reporting also ties the malware to near-zero-interaction browser and Windows exploit chains in the wild.
The malware family provides remote access and post-compromise control, including command execution, file discovery, payload retrieval, and data theft. Recent variants and related evolutions such as SnipBot use multi-stage execution, anti-analysis checks, encrypted strings, registry-stored payloads, COM hijacking, and in-memory execution to hinder detection. Observed functionality includes targeted document collection and exfiltration, deployment of additional modules, and support for proxying or tunneling to facilitate follow-on operations. RomCom activity has also been associated with credential-gathering campaigns and with intrusion tradecraft supporting lateral movement and broader post-exploitation.
Operational use of RomCom spans government, defense, military, telecommunications, finance, manufacturing, logistics, healthcare-support, and critical infrastructure-related targets. The actor behind it has also been linked to ransomware and extortion activity, and reporting describes RomCom as a versatile access platform that can support both intelligence collection and subsequent deployment of other tooling, including ransomware. The family has continued to evolve over several years, with newer iterations showing increased sophistication in delivery, evasion, and operator interaction.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft Threat Intelligece has identified threat actors abusing a recently disclosed vulnerability, CVE-2023-36884, in phishing campaigns containing malicious Word documents against government entities in Europe and North America. | Storm-0978, also known as RomCom is a Russian threat actor known for ransomware, espionage operations, and targeted credential-gathering campaigns. Their latest campaign was last detected in June 2023 involving abuse of CVE-2023-36884 to deliver backdoors over phishing emails according to Microsoft Threat Intelligence.
Later that same year, a Russian hacking group exploited a WinRAR vulnerability tracked as CVE-2025-8088 via phishing attacks to install the RomCom malware.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Proofpoint released “10 Things I Hate about Attribution: RomCom vs. TransferLoader” detailing connections between RomCom and TransferLoader.
Storm-0978, also known as RomCom is a Russian threat actor known for ransomware, espionage operations, and targeted credential-gathering campaigns. Their latest campaign was last detected in June 2023 involving abuse of CVE-2023-36884 to deliver backdoors over phishing emails according to Microsoft Threat Intelligence.
"RomCom malware used the SocGholish fake update loader to deliver Mythic Agent to a U.S. civil engineering firm."
...Void Rabisu APT group is using a remote access trojan called RomCom that uses HTTPS for C&C communications
"...the group’s primary weapon of choice is the RomCom remote access trojan (RAT)—a versatile tool enabling both data exfiltration and ransomware deployment."
29 distinct techniques documented for this family, organized by ATT&CK tactic.
We discovered that 27 domains—24 for TransferLoader and three for RomCom—were deemed likely to turn malicious upon registration.
Microsoft is warning about a phishing campaign from the threat actor known as RomCom that is targeting the defense industry and government entities in Europe and North America.
“they also utilize binary padding techniques… (we've seen a file with 1.7 gigabytes)” / “null bytes are appended to the file…”
“RomCom 3.0 binaries are protected with VMProtect.” / “RomCom uses VMProtect”
This story includes detections for changes to 'ChannelAccess' and 'CustomSD' registry values, as well as the use of tools like 'sc.exe sdset', 'icacls' and 'subinacl' to modify securable objects (files, registry, services, etc) permissions.
“performs detailed network and domain discovery using tools like: netstat, nltest, arp, ping, and PowerShell-based port scans.”
“RomCom 3.0 commands are received as responses to HTTP POST requests…” / “RomCom uses HTTPS for C&C communications”
“After the first-stage downloader is triggered, the malware connects to a command-and-control domain (e.g., drivedefend.com) and pulls down additional payloads, including a Keyprov.dll backdoor.”
“Run AnyDesk on the victim’s machine… send the AnyDesk ID to the C&C server” / “download the AnyDesk executable…”
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RomCom is mentioned as malware installed through exploitation of a WinRAR vulnerability in phishing attacks by a Russian hacking group.
Backdoor malware delivered via malicious RAR archives exploiting CVE-2025-8088 to gain initial access and execute code (e.g., by placing executables in Windows Startup folders).
Loader/backdoor malware used in spear-phishing campaigns, associated with espionage and financial crime operations.
ROMCOM is a backdoor malware typically associated with the Void Rabisu threat group, known for cybercrime and espionage activities aligned with Russian interests. It is often deployed as a final payload in targeted spear-phishing campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.