RomCom is a Windows remote access trojan and backdoor first observed in May 2022, used in both financially motivated intrusions and targeted espionage. It provides remote command and process execution, directory and drive enumeration, filesystem modification, and file upload and download, enabling data theft and deployment of additional malware. It uses HTTPS for command-and-control communications. RomCom is developed and distributed by the Russia-based threat actor tracked as Storm-0978 and Void Rabisu, and has also been deployed in Cuba ransomware intrusions.
RomCom is distributed through phishing and spearphishing, malicious documents, and trojanized installers offered through websites impersonating legitimate software vendors. Campaigns have used Ukrainian political affairs and NATO-related invitations as lures. Exploit-based delivery has included CVE-2023-36884 through Microsoft Word documents in 2023, a chain combining Firefox vulnerability CVE-2024-9680 with Windows Task Scheduler privilege-escalation vulnerability CVE-2024-49039 in 2024, and weaponized WinRAR archives exploiting CVE-2025-8088 in 2025. The Firefox and Windows exploit chain enabled installation without further user interaction after visiting a malicious page.
The family includes PEAPOD, designated RomCom 4.0, and SnipBot, designated RomCom 5.0. SnipBot uses multistage execution, signed initial downloaders, encrypted strings and payloads, and anti-sandbox checks. It establishes persistence through COM hijacking, executes registry-stored payloads, and supports targeted document exfiltration, additional payload execution, SOCKS proxying, and SSH tunneling. RomCom-associated operations have targeted government and military organizations, particularly in Ukraine and among its allies, alongside defense, energy, telecommunications, finance, manufacturing, and logistics organizations in Europe and North America.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Later, in October-November 2024, RomCom executed a sophisticated zero-click attack campaign by chaining two zero-day vulnerabilities: CVE-2024-9680 (a critical use-after-free flaw in Mozilla Firefox's animation component) and CVE-2024-49039 (a Windows privilege escalation flaw allowing escape from the Firefox sandbox).
Microsoft has observed active in-the-wild exploitation of this vulnerability using specially crafted Microsoft Office documents. Unit 42 Threat Intelligence can confirm that this vulnerability has been utilized since at least July 3, 2023.
CVE-2024-49039 (a Windows privilege escalation flaw allowing escape from the Firefox sandbox). By luring victims with vulnerable Firefox versions to specially crafted websites [...] the attackers could execute arbitrary code and install the RomCom backdoor without user interaction.
Later that same year, a Russian hacking group exploited a WinRAR vulnerability tracked as CVE-2025-8088 via phishing attacks to install the RomCom malware.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“The group is known for developing and distributing the RomCom backdoor, frequently delivered through these compromised software installers.” The campaign sample was detected by ESET as Win32/TrojanDownloader.RomCom.A.
According to Palo Alto Networks Unit 42, Cuba ransomware actors began using RomCom malware, a custom RAT, for command and control (C2).
According to Palo Alto Networks Unit 42, Cuba ransomware actors began using RomCom malware, a custom RAT, for command and control (C2).
Proofpoint released “10 Things I Hate about Attribution: RomCom vs. TransferLoader” detailing connections between RomCom and TransferLoader.
"RomCom malware used the SocGholish fake update loader to deliver Mythic Agent to a U.S. civil engineering firm."
...Void Rabisu APT group is using a remote access trojan called RomCom that uses HTTPS for C&C communications
29 distinct techniques documented for this family, organized by ATT&CK tactic.
We discovered that 27 domains—24 for TransferLoader and three for RomCom—were deemed likely to turn malicious upon registration.
Microsoft is warning about a phishing campaign from the threat actor known as RomCom that is targeting the defense industry and government entities in Europe and North America.
“they also utilize binary padding techniques… (we've seen a file with 1.7 gigabytes)” / “null bytes are appended to the file…”
“RomCom 3.0 binaries are protected with VMProtect.” / “RomCom uses VMProtect”
“performs detailed network and domain discovery using tools like: netstat, nltest, arp, ping, and PowerShell-based port scans.”
“RomCom 3.0 commands are received as responses to HTTP POST requests…” / “RomCom uses HTTPS for C&C communications”
“After the first-stage downloader is triggered, the malware connects to a command-and-control domain (e.g., drivedefend.com) and pulls down additional payloads, including a Keyprov.dll backdoor.”
“Run AnyDesk on the victim’s machine… send the AnyDesk ID to the C&C server” / “download the AnyDesk executable…”
67 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor associated with Void Rabisu; the report notes it has undergone multiple enhancements and is considered an advanced piece of malware.
RomCom is mentioned as malware installed through exploitation of a WinRAR vulnerability in phishing attacks by a Russian hacking group.
Backdoor malware delivered via malicious RAR archives exploiting CVE-2025-8088 to gain initial access and execute code (e.g., by placing executables in Windows Startup folders).
Loader/backdoor malware used in spear-phishing campaigns, associated with espionage and financial crime operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.