RomCom is a Russia-aligned threat actor, also tracked as Storm-0978, Tropical Scorpius, UNC2596, UNC4895, Underground Team, and Void Rabisu. The content describes it as a Russia-based group that has conducted both financially motivated cybercrime and targeted espionage operations, with reporting noting a shift toward intelligence collection alongside conventional criminal activity. It has targeted defense, government, telecom, and financial organizations in Europe and North America, as well as financial, manufacturing, defense, and logistics companies in Europe and Canada. Multiple reports state that the group has consistently targeted organizations with links to Ukraine and projects supporting Ukraine. RomCom has used spearphishing, highly targeted phishing emails, fake software updates, trojanized legitimate software, and access obtained via initial access brokers. Reported lures included NATO Summit invitations, Ukrainian World Congress themes, fake job applications, and application-document themed archives. The group has distributed RomCom backdoors through trojanized versions of legitimate software including Adobe products, Advanced IP Scanner, SolarWinds Network Performance Monitor, SolarWinds Orion, KeePass, and Signal. Arctic Wolf reported that RomCom also used SocGholish to deliver Mythic Agent. The actor has repeatedly exploited client-side vulnerabilities for intrusion. Microsoft linked Storm-0978 to exploitation of CVE-2023-36884 via specially crafted Microsoft Word documents in campaigns against European and North American government and defense targets. ESET reported that RomCom exploited the WinRAR zero-day CVE-2025-8088 in targeted spearphishing campaigns observed in July 2025, delivering RomCom-associated payloads including a SnipBot variant, RustyClaw, and Mythic Agent. The content states this was at least the third time RomCom had been observed exploiting a significant zero-day in the wild. Associated malware and operations in the content include RomCom backdoors, SnipBot, RustyClaw, Mythic Agent, and Underground ransomware. The Underground ransomware is described as likely spread by RomCom and as using CVE-2023-36884, phishing emails, and initial access brokers for access. The content also notes RomCom’s use of SystemBC and references a relationship or partnership between RomCom and Trickbot as part of a broader Russian privateer-style ecosystem. The group is described as operating out of Russia, and several sources characterize it as Russia-aligned or linked to Russian cyber operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
25 malware families attributed to this actor across reporting.
20 additional families tracked in Mallory.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
As recently as November 2025, an email phishing wave targeting Ukraine was found to deliver the implant via RAR archives that exploit CVE-2025-8088, a WinRAR vulnerability that has been exploited by a number of Russian hacking groups such as Sandworm, Gamaredon, and RomCom.
Historical parallels, such as the exploitation of CVE-2023-36884 by Storm-0978, underscore how Office-based RCE vulnerabilities have been weaponized for targeted intrusions.
GTIG spotlighted CIGAR (UNC4895/RomCom) deploying a zero-day chain against Firefox and Windows (CVE-2024-49039) that escalated privileges from low integrity to SYSTEM via Windows RPC abuse, enabling creation/execution of scheduled tasks as SYSTEM.
"Attackers were observed chaining this vulnerability with a remote code execution flaw in Firefox, identified as CVE-2024-9680."
Next the threat actors attempted to use a file called zero.exe, which is used to exploit the Zerologon vulnerability to escalate privileges.
3 more CVEs tied to this actor tracked in Mallory.
51 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as one of several Russian hacking groups known to have exploited the WinRAR vulnerability CVE-2025-8088.
Used SocGholish to deliver Mythic Agent, demonstrating use of SocGholish as an initial access broker service.
Russia-linked threat actor also reported as exploiting CVE-2025-8088.
Reported as one of the Russia-aligned threat actors that exploited CVE-2025-8088 earlier in the year.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.