RomCom — APT Profile
RomCom (Storm-0978, Void Rabisu, Tropical Scorpius, UNC2596) is a Russia-aligned group that blends financially motivated cybercrime with espionage supporting Russian state interests. It delivers its signature RomCom RAT backdoor via trojanized software installers, spearphishing, and repeated zero-day exploitation. Microsoft tied the group to CVE-2023-36884 (Office/Windows HTML RCE) in June-July 2023 phishing that used Ukrainian World Congress and NATO Summit lures; in November 2024 ESET exposed a chained Firefox use-after-free (CVE-2024-9680) and Windows Task Scheduler privilege escalation (CVE-2024-49039) that installed the backdoor with no user interaction; and in July 2025 ESET caught the group exploiting a WinRAR path traversal zero-day (CVE-2025-8088) against financial, manufacturing, defense, and logistics companies in Europe and Canada. Earlier operations overlapped with the Cuba ransomware ecosystem, and Microsoft has also linked it to Industrial Spy and Underground ransomware. Espionage focuses on government and defense entities in Ukraine, Europe, and North America.Also tracked as
UNC2596, Tropical Scorpius, Void Rabisu, TA829, Cuba, Dire Flux, Fidel Ransomware, COLDDRAW, Storm-0978
Tools & malware
- BUGHATCH Downloader
- BURNTCIGAR EDR-killer / kernel process terminator
- Cobalt Strike BEACON C2 / post-exploitation framework
- COLDDRAW (Cuba encryptor) Ransomware
- KerberCache Kerberos ticket extraction tool
- Mimikatz Credential theft
- NetSupport RAT Remote access tool
- PocLowIL Exploit
- PsExec Lateral movement utility
- RomCom Backdoor Backdoor
- RomCom RAT Remote Access Trojan
- ROMCOM RAT Remote access trojan
- SingleCamper Backdoor
- SystemBC Proxy / backdoor
- TERMITE Memory-only dropper
- Veeamp Credential stealer (Veeam)
- WEDGECUT Reconnaissance tool
- ZeroLogon (CVE-2020-1472) Privilege escalation exploit
Recent claimed victims
- dms-imaging 2024-02-01
- deknudtframes.be 2024-01-22
Vendor research
- Hacker uses new RAT malware in Cuba Ransomware attacks BleepingComputer
- #StopRansomware: Cuba Ransomware (AA22-335A) CISA / FBI
- (Ex)Change of Pace: UNC2596 Observed Leveraging Vulnerabilities to Deploy Cuba Ransomware Mandiant
- Novel News on Cuba Ransomware: Greetings From Tropical Scorpius Palo Alto Networks Unit 42
- From Caribbean shores to your devices: analyzing Cuba ransomware Kaspersky (Securelist)
- Storm-0978 Threat Actor Profile Microsoft
- RomCom Threat Actor Abuses KeePass and SolarWinds BlackBerry
- RomCom Threat Actor Suspected of Targeting Ukraine NATO Summit Guests Unit 42
- RomCom Exploits Firefox and Windows Zero-Days in the Wild ESET