RomCom — APT Profile

RomCom, tracked by Microsoft as Storm-0978 and by Trend Micro as Void Rabisu, has burned a zero-day in three consecutive years while blending financially motivated cybercrime with espionage that serves Russian state interests. Microsoft, which calls it a cybercriminal group based out of Russia, tied it to CVE-2023-36884 (Office and Windows HTML RCE) in June and July 2023 phishing that used Ukrainian World Congress and NATO Summit lures, and links it to Industrial Spy, Underground and Trigona ransomware. ESET documented a chained Firefox use-after-free (CVE-2024-9680) and Windows Task Scheduler privilege escalation (CVE-2024-49039) in November 2024 that installed the backdoor with no user interaction, then in August 2025 reported exploitation of a WinRAR path traversal zero-day (CVE-2025-8088) between 18 and 21 July 2025 against financial, manufacturing, defense and logistics companies in Europe and Canada, delivering a SnipBot variant, the RustyClaw and MeltingClaw downloaders and a Mythic agent. Arctic Wolf reported in November 2025 that a September 2025 intrusion at a US civil engineering firm with Ukraine ties delivered RomCom's Mythic agent loader through a SocGholish fake update chain, and assessed with medium to high confidence that Russia's GRU Unit 29155 is using SocGholish to target victims. Earlier activity overlapped with the Cuba ransomware ecosystem, though CISA and the FBI describe only a possible link between Cuba ransomware actors, RomCom RAT actors and Industrial Spy ransomware actors.

Also tracked as

UNC2596, Tropical Scorpius, Void Rabisu, TA829, Cuba, Dire Flux, Fidel Ransomware, COLDDRAW, Storm-0978, CIGAR, Nebulous Mantis, UAT-5647

Tools & malware

Recent claimed victims

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions