Home/Threat Actor/RomCom
Threat Actor

RomCom

romcom · russia_speaking_organized_cybercrime_state_aligned_hybrid · active since 2022

RomCom (Microsoft Storm-0978 [formerly DEV-0978].

Palo Alto Unit 42 Tropical Scorpius / Transforming Scorpius.

Cisco Talos UAT-5647.

Trend Micro Void Rabisu.

Mandiant UNC2596; CERT-UA UAC-0180.

Symantec Hawker for Cuba-developer-linked cluster) is a Russia-speaking hybrid threat actor cluster active since 2022 that operationally combines opportunistic financially-motivated ransomware-and-extortion operations with targeted state-aligned-espionage operations against Ukrainian government and military targets plus Ukrainian- affiliated organizations in NATO partner countries, an operationally-distinctive dual-track operational pattern that Microsoft's canonical July 2023 Storm-0978 disclosure analytically separated as "two operational tracks operating simultaneously under the same operator umbrella".

signature custom backdoor family is the RomCom RAT (versions 1.0 through 5.0 / SingleCamper / SnipBot) with multi-language tooling investment (GoLang, C++, Rust, Lua) including DustyHammock, ShadyHammock, RustyClaw, MeltingClaw, and Mythic Agent payloads.

multiple-ransomware-family-deployment pattern (Cuba, Industrial Spy, Underground, Trigona, and RomCom-own ransomware)

operationally-distinctive zero-day acquisition-and-research capability demonstrated across three publicly-confirmed zero-day exploitation campaigns (CVE-2023-36884 Microsoft Office July 2023; CVE-2024-9680 Mozilla Firefox/Thunderbird + CVE-2024-49039 Windows kernel chain October-November 2024.

CVE-2025-8088 WinRAR July-August 2025), operationally distinguishing the cluster from typical organized-cybercrime operators; signature trojanized-legitimate-software distribution pattern (Adobe, Advanced IP Scanner, SolarWinds NPM/Orion, KeePass, Signal)

strong technical-and-infrastructure links to Hawker / Cuba ransomware developer cluster (CISA-assessed possible operational links between Hawker, RomCom, and Industrial Spy ransomware operators)

fills the modern hybrid-Russia-aligned cluster cell in the curated corpus complementing broader Russian state-sponsored APT and Russia-speaking organized-cybercrime coverage.

russia_speaking_organized_cybercrime_state_aligned_hybrid confidence: high 21 aliases

Profile

RomCom (also tracked as Microsoft DEV-0978 [legacy] and Storm-0978 [current Microsoft naming].

Palo Alto Networks Unit 42 Tropical Scorpius / Transforming Scorpius.

Cisco Talos UAT-5647.

Trend Micro Void Rabisu.

Mandiant UNC2596; CERT-UA UAC-0180.

Symantec / Broadcom Hawker [for the Cuba-ransomware-developer cluster operationally-linked to RomCom]) is a Russia-speaking hybrid threat actor cluster active publicly since 2022. The cluster is operationally distinctive for blurring the line between organized cyber- criminal financially-motivated activity and state-aligned cyber-espionage targeting in support of Russian geopolitical interests, operating two simultaneous operational tracks under the same operator umbrella that Microsoft's canonical July 2023 Storm-0978 disclosure analytically separated as: (a) opportunistic ransomware-and-extortion operations against financial-sector and other commercial-sector targets (financially-motivated track), and (b) targeted credential- gathering and espionage operations against Ukrainian government, military, and Ukrainian-affiliated organizations in Europe, North America, and broader NATO partner countries (state-aligned-espionage track). The hybrid dual-track operational pattern is operationally distinctive in modern cyber-threat-intelligence reporting and has prompted analytical debate as to whether the cluster operates under Russian state coordination, under Russian state tolerance, or as an organized-cybercrime cluster that operationally selects targets in alignment with Russian geopolitical interests. No formal Russian state-sponsorship attribution has been asserted by any government cybersecurity authority, but the cluster's operational targeting alignment with Russian geopolitical interests in Ukraine is operationally consistent with state-tolerated-with-targeting-coordination operations. The cluster's operational signature is the RomCom RAT custom backdoor family (developed and operated exclusively by the cluster) and the cluster's name is derived from this signature backdoor. RomCom RAT operational versions have evolved iteratively across the cluster's operational history through five publicly-tracked major versions, with version 5.0 (Cisco Talos naming SingleCamper, also tracked as SnipBot) operationally distinctive for loading directly from the Windows registry into memory using a loopback address to communicate with its loader, providing operationally- distinctive in-memory persistence-and-execution tradecraft. Additional cluster custom backdoor families include DustyHammock (Rust-based late-stage backdoor), ShadyHammock (C++-based backdoor predecessor to DustyHammock), and multi-language downloaders RustyClaw and MeltingClaw. The cluster's multi-language tooling investment (GoLang, C++, Rust, Lua) demonstrates sustained operational-development capability across multiple programming-language ecosystems , operationally distinguishing the cluster from typical organized-cybercrime clusters that operate predominantly in a single programming-language ecosystem. The cluster's signature operational tradecraft includes: (1) ZERO-DAY EXPLOIT ACQUISITION-AND-RESEARCH CAPABILITY. The cluster is one of the only publicly-attributed clusters with three distinct publicly-confirmed zero-day exploitation campaigns across an approximately two-year operational window: (a) CVE-2023-36884 Microsoft Office/Windows HTML RCE (July 2023 exploitation, canonical Microsoft Storm-0978 disclosure attribution)

(b) CVE-2024-9680 Mozilla Firefox/ Thunderbird Animation Timeline UAF + CVE-2024-49039 Windows kernel privilege escalation chained zero-click exploit (October-November 2024)

(c) CVE-2025-8088 WinRAR path- traversal (July-August 2025, ESET disclosure). The operational pattern is operationally distinctive versus typical organized-cybercrime clusters and operationally suggests state-tolerated-or-state-aligned access to zero- day inventories beyond what financially-motivated organized- cybercrime clusters typically have. Industry-rate-card valuation for unpatched Microsoft Office and Firefox / Thunderbird remote-code-execution capability exceeds approximately US$100,000-150,000 per exploit.

the cluster's demonstrated multi-zero-day-deployment operational pattern represents significant operational-capability investment. (2) MULTIPLE-RANSOMWARE-FAMILY-DEPLOYMENT PATTERN. The cluster operationally deploys multiple distinct ransomware payloads across operational campaigns rather than developing a single signature ransomware encryptor (operationally similar to FIN8, separately curated as fin8.yaml, in this operational pattern dimension): Cuba ransomware (historical operational overlap.

strong technical-and-infrastructure links with the Hawker cluster Symantec tracks as Cuba's developer)

Industrial Spy ransomware (2022 onward); Underground ransomware (2023 onward, operationally related to Industrial Spy)

Trigona ransomware (observed in at least one operation)

RomCom-own-developed ransomware family (2023 onward). The Cuba ransomware operations are curated separately in this corpus as cuba_ransomware.yaml.

CISA has assessed possible operational links between Hawker (Cuba developer), RomCom, and the Industrial Spy ransomware operators. (3) TROJANIZED LEGITIMATE-SOFTWARE DISTRIBUTION SIGNATURE PATTERN. The cluster operationally distributes trojanized versions of popular legitimate software (Adobe products, Advanced IP Scanner, SolarWinds Network Performance Monitor, SolarWinds Orion, KeePass, Signal Messenger, others) from malicious domains impersonating the legitimate-software- vendor download sites (e.g., advanced-ip-scaner[.]com, missing "n", masquerading as Advanced IP Scanner). The trojanized installers deliver the RomCom RAT alongside the legitimate-software functionality to evade immediate detection by the user. The pattern is operationally distinctive across the cluster's longitudinal operational history. (4) EDGE-DEVICE PIVOT TRADECRAFT VIA PUTTY PLINK. Cisco Talos UAT-5647 disclosure documented the cluster's signature tradecraft of targeting edge devices from inside compromised networks using PuTTY Plink reverse-tunneling to map internal admin ports of edge devices to attacker-controlled remote servers. The edge-device pivot tradecraft supports long- term-persistence operational goals consistent with the cluster's state-aligned-espionage operational track. (5) SUSTAINED UKRAINIAN AND UKRAINIAN-AFFILIATED TARGETING. Following the Russian February 2022 invasion of Ukraine, the cluster has sustainedly targeted Ukrainian government, military, and Ukrainian-affiliated organizations alongside continued opportunistic financially-motivated ransomware operations. The October 2023 PEAPOD campaign (Trend Micro tracking) extended targeting to women political leaders in multiple European countries through targeted social- engineering operations impersonating legitimate political- conference and human-rights-organization communications. Operational tempo of Ukrainian-targeting operations correlates with Russian-Ukrainian war developments and Ukrainian- government cyber-defense responses. (6) CREDENTIAL HARVESTING + SAM HASH DUMP IN RANSOMWARE OPERATIONS. Microsoft Storm-0978 disclosure documented the cluster's signature tradecraft in ransomware operations of dumping password hashes from the Windows Security Account Manager (SAM) using the Windows registry, requiring SYSTEM- level privileges that the cluster typically acquires via privilege-escalation operations during the post-compromise phase. Targeted sectors across the cluster's operational history include government administration, defense and military, foreign affairs ministries, intelligence services, critical infrastructure, energy, telecommunications, financial services, banking, insurance, manufacturing, logistics and supply chain, technology, IT services, higher education, research institutes, non-governmental organizations, political organizations, media and journalism, pharmaceutical and healthcare, and individually-targeted women political leaders (PEAPOD October 2023 campaign). Targeted geographies are primarily Ukraine (sustained state-aligned-targeting geography), Poland (signature secondary targeting), and broader Western and Central-Eastern European NATO member countries (United States, United Kingdom, Germany, France, Belgium, Netherlands, Italy, Canada, Latvia, Lithuania, Estonia, and others). The cluster is operationally significant as one of the most operationally-distinctive examples of hybrid criminal-and- state-aligned cyber operations in modern cyber-threat- intelligence reporting. The cluster's sustained operational tempo across approximately three-plus years, demonstrated multi-zero-day-deployment operational capability, multi- language-tooling-development investment, multi-ransomware- family-deployment operational pattern, and operationally- coordinated targeting alignment with Russian geopolitical interests in Ukraine make RomCom one of the highest-impact Russia-aligned threat-actor clusters in the modern post- February-2022 operational period. The cluster fills the modern hybrid-Russia-aligned-cluster cell in this corpus, complementing the broader Russian state-sponsored APT coverage (apt28_fancybear.yaml, apt29_cozybear.yaml, sandworm_team.yaml, turla.yaml, cadet_blizzard.yaml, dragonfly_energetic_bear.yaml, gamaredon.yaml, star_blizzard_callisto.yaml) and the broader Russia-speaking organized-cybercrime ransomware coverage (alphv_blackcat.yaml, darkside_blackmatter.yaml, revil_sodinokibi.yaml, wizard_spider_conti.yaml, cuba_ransomware.yaml, and others).

Aliases

21
storm-0978storm0978dev-0978dev0978deb-0978tropical scorpiustransforming scorpiusuat-5647uat5647void rabisuvoidrabisuunc2596unc-2596uac-0180uac0180romcom rat operatorsromcom actorromcom grouphawkerrom comrom_com

Notable Campaigns

8
2025WinRAR CVE-2025-8088 Path-Traversal Zero-Day Exploitation (July-August 2025)
2024Firefox / Thunderbird CVE-2024-9680 + Windows CVE-2024-49039 Zero-Day Chain (October-November 2024)
2024Cisco Talos UAT-5647 Disclosure: SingleCamper / RomCom 5.0 + Multi-Language Tooling (October 2024)
2023Microsoft Office / Windows HTML CVE-2023-36884 Zero-Day Exploitation (June-July 2023)
2023PEAPOD Cyber-Attack Campaign Targeting Women Political Leaders (October 2023)
2022-presentUkraine War Operational-Pivot, Sustained Ukrainian Targeting (February 2022 onward)
2022-presentTrojanized Legitimate-Software Distribution Signature Pattern (2022 - Present)
2022RomCom Operational Emergence and Cuba Ransomware Operational Overlap (2022)

Attribution & Reporting

Attributed by
Microsoft Threat Intelligence CenterPalo Alto Networks Unit 42Cisco TalosTrend MicroMandiantGoogle Cloud Threat IntelligenceCERT-UA (Computer Emergency Response Team of Ukraine)Symantec / Broadcom Threat Hunter TeamCrowdStrikeESETBlackBerry Threat Research and IntelligenceVolexityTrellixRecorded Future Insikt GroupSentinelOneProofpointCheckPoint ResearchUS CISAUS FBI
Key reporting
reportMicrosoft Threat Intelligence Center: Storm-0978 Attacks Reveal Financial and Espionage Motives (July 11, 2023), canonical industry vendor reference
reportCisco Talos: UAT-5647 Targets Ukrainian and Polish Entities with RomCom Malware Variants (October 17, 2024), canonical SingleCamper / RomCom 5.0 + multi-language tooling disclosure
reportTrend Micro: Void Rabisu Targets Female Political Leaders with PEAPOD Cyberattack (October 13, 2023)
reportPalo Alto Networks Unit 42: Tropical Scorpius / Transforming Scorpius Operational Tracking (multiple years)
reportESET Research: Update WinRAR Tools Now, RomCom and Others Exploiting CVE-2025-8088 Zero-Day (August 2025)
reportHelp Net Security: RomCom Hackers Chained Firefox and Windows Zero-Days to Deliver Backdoor (November 26, 2024)
reportMandiant / Google Cloud Threat Intelligence: UNC2596 Operational Tracking (multiple years)
reportSymantec / Broadcom Threat Hunter Team: Hawker Operational Profile (Cuba ransomware developer cluster, operationally-linked to RomCom)
reportCERT-UA: UAC-0180 Operational Alerts (multiple Ukrainian-government-targeting campaigns)
reportCrowdStrike: RomCom Threat Profile (multiple years)
reportBlackBerry Threat Research and Intelligence: RomCom Operational Analysis
reportVolexity: RomCom Operational Tracking
reportProofpoint: RomCom vs TransferLoader Attribution Analysis (June 2024)
reportTrellix: RomCom Continued Operational Tracking
reportRecorded Future Insikt Group: RomCom / Storm-0978 Tracking
reportSentinelOne: RomCom Continued Tracking
reportPicus Security Labs: RomCom Threat Actor Evolution 2023-2025
reportMalpedia Actor Profile: Void Rabisu / RomCom
reportMalpedia Malware Profile: RomCom RAT

Operational

State sponsor

Russia-speaking hybrid threat actor cluster operationally distinctive for blurring the line between organized cyber-criminal financially-motivated activity and state- aligned cyber-espionage targeting in support of Russian geopolitical interests. Industry vendor attribution (Microsoft Threat Intelligence Center, Unit 42 Palo Alto Networks, Cisco Talos, Trend Micro, Mandiant / Google Cloud Threat Intelligence, CERT-UA, Symantec / Broadcom) is consistent in attributing the cluster to Russia-speaking operators based on operational targeting patterns (sustained targeting of Ukraine, Ukrainian-government allies in NATO countries, and Ukrainian-affiliated organizations following the Russian February 2022 invasion of Ukraine), operator language artifacts, infrastructure provider patterns, and operational tradecraft consistent with the broader Russia- speaking organized-cybercrime ecosystem. The cluster's operational signature is dual-track operations: (a) opportunistic ransomware-and-extortion operations against financial-sector and other commercial-sector targets (financially-motivated track), and (b) targeted credential- gathering and espionage operations against Ukrainian government, military, and Ukrainian-affiliated organizations in Europe, North America, and broader NATO partner countries (state-aligned-espionage track). Microsoft's July 2023 Storm-0978 canonical disclosure analytically separated the two operational tracks: ransomware operations are described as "largely opportunistic in nature and entirely separate from espionage-focused targets," while espionage operations are described as targeting Ukrainian government and military organizations and Ukrainian-affiliated organizations in Europe and North America. The operational hybrid pattern is operationally distinctive in modern cyber-threat-intelligence reporting and has prompted analytical debate as to whether the cluster operates under Russian state coordination, under Russian state tolerance, or as an organized-cybercrime cluster that operationally selects targets in alignment with Russian geopolitical interests. Strong technical-and- infrastructure links between RomCom / Storm-0978 and the Hawker cluster (Symantec naming), developer of the Cuba ransomware family, have been observed, with Symantec analysis suggesting the two clusters may be the same actor or strongly operationally-coordinated. CISA has assessed possible operational links between Hawker, RomCom, and the Industrial Spy ransomware operators. The Cuba ransomware family operations are curated separately in this corpus as cuba_ransomware.yaml.

RomCom is curated as the broader hybrid cluster operating the RomCom RAT and multiple sequential ransomware-family deployments. No formal Russian state-sponsorship attribution has been asserted by any government cybersecurity authority, but the cluster's operational targeting alignment with Russian geopolitical interests in Ukraine is operationally consistent with state-tolerated-with-targeting-coordination operations.

Motivations
financial_ransom_opportunistic, data_theft_and_extortion, cyber_espionage_targeting_ukraine_and_ukrainian_allies, credential_gathering_for_state_aligned_intelligence_operations, information_operations_and_political_disruption
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)34/60 · 56%
Runtime / container (Falco)5/60 · 8%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MELTINGCLAWMYTHIC AGENTSHADYHAMMOCKSINGLECAMPERSNIPBOT
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin