RomCom — APT Profile

RomCom (Storm-0978, Void Rabisu, Tropical Scorpius, UNC2596) is a Russia-aligned group that blends financially motivated cybercrime with espionage supporting Russian state interests. It delivers its signature RomCom RAT backdoor via trojanized software installers, spearphishing, and repeated zero-day exploitation. Microsoft tied the group to CVE-2023-36884 (Office/Windows HTML RCE) in June-July 2023 phishing that used Ukrainian World Congress and NATO Summit lures; in November 2024 ESET exposed a chained Firefox use-after-free (CVE-2024-9680) and Windows Task Scheduler privilege escalation (CVE-2024-49039) that installed the backdoor with no user interaction; and in July 2025 ESET caught the group exploiting a WinRAR path traversal zero-day (CVE-2025-8088) against financial, manufacturing, defense, and logistics companies in Europe and Canada. Earlier operations overlapped with the Cuba ransomware ecosystem, and Microsoft has also linked it to Industrial Spy and Underground ransomware. Espionage focuses on government and defense entities in Ukraine, Europe, and North America.

Also tracked as

UNC2596, Tropical Scorpius, Void Rabisu, TA829, Cuba, Dire Flux, Fidel Ransomware, COLDDRAW, Storm-0978

Tools & malware

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions