RomCom — APT Profile
RomCom, tracked by Microsoft as Storm-0978 and by Trend Micro as Void Rabisu, has burned a zero-day in three consecutive years while blending financially motivated cybercrime with espionage that serves Russian state interests. Microsoft, which calls it a cybercriminal group based out of Russia, tied it to CVE-2023-36884 (Office and Windows HTML RCE) in June and July 2023 phishing that used Ukrainian World Congress and NATO Summit lures, and links it to Industrial Spy, Underground and Trigona ransomware. ESET documented a chained Firefox use-after-free (CVE-2024-9680) and Windows Task Scheduler privilege escalation (CVE-2024-49039) in November 2024 that installed the backdoor with no user interaction, then in August 2025 reported exploitation of a WinRAR path traversal zero-day (CVE-2025-8088) between 18 and 21 July 2025 against financial, manufacturing, defense and logistics companies in Europe and Canada, delivering a SnipBot variant, the RustyClaw and MeltingClaw downloaders and a Mythic agent. Arctic Wolf reported in November 2025 that a September 2025 intrusion at a US civil engineering firm with Ukraine ties delivered RomCom's Mythic agent loader through a SocGholish fake update chain, and assessed with medium to high confidence that Russia's GRU Unit 29155 is using SocGholish to target victims. Earlier activity overlapped with the Cuba ransomware ecosystem, though CISA and the FBI describe only a possible link between Cuba ransomware actors, RomCom RAT actors and Industrial Spy ransomware actors.Also tracked as
UNC2596, Tropical Scorpius, Void Rabisu, TA829, Cuba, Dire Flux, Fidel Ransomware, COLDDRAW, Storm-0978, CIGAR, Nebulous Mantis, UAT-5647
Tools & malware
- BUGHATCH Downloader
- BURNTCIGAR EDR-killer / kernel process terminator
- Cobalt Strike BEACON C2 / post-exploitation framework
- COLDDRAW (Cuba encryptor) Ransomware
- KerberCache Kerberos ticket extraction tool
- MeltingClaw Downloader
- Mimikatz Credential theft
- Mythic Agent C2 agent
- NetSupport RAT Remote access tool
- PocLowIL Exploit
- PsExec Lateral movement utility
- RomCom Backdoor Backdoor
- RomCom RAT Remote Access Trojan
- RustyClaw Downloader
- SingleCamper Backdoor
- SnipBot Backdoor
- SystemBC Proxy / backdoor
- TERMITE Memory-only dropper
- Veeamp Credential stealer (Veeam)
- WEDGECUT Reconnaissance tool
- ZeroLogon (CVE-2020-1472) Privilege escalation exploit
Recent claimed victims
- dms-imaging 2024-02-01
- deknudtframes.be 2024-01-22
Vendor research
- Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability ESET
- 10 Things I Hate About Attribution: RomCom vs. TransferLoader Proofpoint
- Russian RomCom Utilizing SocGholish to Deliver Mythic Agent to U.S. Companies Supporting Ukraine Arctic Wolf
- Novel News on Cuba Ransomware: Greetings From Tropical Scorpius Palo Alto Networks Unit 42
- #StopRansomware: Cuba Ransomware (AA22-335A) CISA / FBI
- (Ex)Change of Pace: UNC2596 Observed Leveraging Vulnerabilities to Deploy Cuba Ransomware Mandiant
- From Caribbean shores to your devices: analyzing Cuba ransomware Kaspersky (Securelist)
- Hacker uses new RAT malware in Cuba Ransomware attacks BleepingComputer
- Storm-0978 Threat Actor Profile Microsoft
- RomCom Threat Actor Suspected of Targeting Ukraine NATO Summit Guests Unit 42
- RomCom Exploits Firefox and Windows Zero-Days in the Wild ESET
- RomCom Threat Actor Abuses KeePass and SolarWinds BlackBerry
Countries linked to this actor
- Montenegro targets