RomCom RAT is a Windows remote access trojan and backdoor associated with the RomCom threat actor cluster, also tracked under names including Storm-0978, Tropical Scorpius, UAC-0180, UNC2596, Void Rabisu, CIGAR, and in some reporting TA829 or Nebulous Mantis. Active since at least 2022, it has been used in both espionage and financially motivated operations, including campaigns targeting Ukrainian and Polish entities, as well as government, critical infrastructure, political, defense, and other organizations in Europe and North America.
The malware is designed to establish persistent remote control over compromised endpoints. Reported capabilities include command execution, reverse shell access, file upload and download, deletion of files and directories, process and drive enumeration, installed software discovery, screenshot capture, browser-data-related payload execution, and retrieval or execution of additional modules. Some variants perform system reconnaissance, harvest credentials, enumerate Active Directory, support lateral movement, and collect data such as files, configuration details, and Outlook backups. RomCom RAT has also been described as using encrypted command-and-control communications, with some observed versions supporting HTTP communications and fallback mechanisms, and later variants expanding functionality and privilege through scheduled-task abuse.
RomCom RAT has been delivered through multiple intrusion vectors. Documented distribution methods include spearphishing and phishing campaigns, fake software download lures, compromised or attacker-controlled websites, and exploit-driven delivery. The malware has also been deployed through chained exploitation of major vulnerabilities, including Firefox and Windows zero-days in 2024 that enabled code execution, sandbox escape, and elevated privileges before installation of the backdoor. Earlier campaigns were also linked to exploitation of Microsoft Word and browser-related attack surfaces.
Operationally, RomCom RAT often serves as an initial foothold or post-compromise backdoor within a broader intrusion chain. After establishing access, operators have been observed deploying additional loaders or follow-on tooling to deepen compromise, deliver further payloads, support ransomware operations, or conduct espionage and data theft. Persistence has been linked to techniques such as COM hijacking. The malware is actively maintained, with multiple variants and staged architectures reported, including DLL-based first stages and later implants that execute commands and fetch additional payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
RomCom RAT is used by threat actors to create a backdoor for remotely controlling endpoint computers. The Russian-linked TA829 group uses this and other tools for intelligence-gathering as well as financial fraud.
RomCom RAT is used by threat actors to create a backdoor for remotely controlling endpoint computers. The Russian-linked TA829 group uses this and other tools for intelligence-gathering as well as financial fraud.
Specifically, this involves: A new malware family that Unit 42 tracks as ROMCOM RAT.
"...Nebulous Mantis that has deployed a remote access trojan called RomCom RAT since mid-2022."
29 distinct techniques documented for this family, organized by ATT&CK tactic.
"Nebulous Mantis imitates trusted services like OneDrive to trick victims into downloading infected files, often hosted on Mediafire."
"...collect data of interest, including files, credentials, configuration details, and Microsoft Outlook backups."
These include downloading payloads specifically designed to take single or multiple screenshots of a system
ROMCOM will gather system and user information, and attempt to send it to a hardcoded C2 server via the WinHTTP API.
ROMCOM will gather system and user information, and attempt to send it to a hardcoded C2 server via the WinHTTP API.
The received data from this second request is then passed into a function that first connects to the local address 127.0.0[.]3 over a port between 5555 and 5600... ROMCOM binds to 127.0.0[.]2:5555, where it will wait for a connection and forward any data received from that connection to its C2 server.
If the connection fails, ROMCOM attempts to connect to and communicate with the C2 server using ICMP requests.
"The first-stage RomCom DLL is designed to connect to a C2 server and download additional payloads using the InterPlanetary File System (IPFS)..."
Start up a reverse shell under the name svchelper.exe within the %ProgramData% folder
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan used by Nebulous Mantis; uses evasion/LOTL tactics and encrypted C2 (as described).
Remote access trojan referenced in connection with a threat actor cluster (TA829) and overlapping tactics/infrastructure with TransferLoader activity.
Remote access trojan used to establish a backdoor for remote control of compromised endpoints. The content says it is distributed via phishing campaigns, compromised URLs, and fake software downloads, and has been used for intelligence-gathering, financial fraud, and earlier operations against Ukrainian and Polish targets.
Remote access trojan used by the Russia-aligned TA829 for espionage and financial-motivated activity; delivered via phishing tactics (spoofed senders, PDF lures, redirect links) and supported by infrastructure that filters out sandboxed systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.