RomCom
RomCom is a Russia-linked threat actor also tracked as Storm-0978, Tropical Scorpius, UNC2596, UNC4895, CIGAR, Void Rabisu, Underground Team, and in some reporting Storm-0671. The content describes the group as operating out of Russia and as a mixed-motive actor conducting both financially motivated cybercrime and espionage, including ransomware and extortion activity alongside intelligence-collecting operations. Multiple sources in the content characterize the group as Russia-aligned; one cited assessment attributes RomCom activity with medium-to-high confidence to Russia’s GRU Unit 29155. RomCom has targeted defense industry and government entities in Europe and North America, as well as telecom and financial organizations. Additional targeting described in the content includes organizations with ties to projects supporting Ukraine, and financial, manufacturing, defense, and logistics firms in Europe and Canada. The content states the group has consistently targeted entities linked to Ukraine and its defense against Russia. The group is associated with spearphishing and highly targeted phishing campaigns, including lures themed around the Ukrainian World Congress, NATO Summit invitations, and fake job applications or CVs. It has exploited multiple zero-days in the wild. The content specifically links RomCom to exploitation of CVE-2023-36884, a Microsoft Office and Windows remote code execution vulnerability delivered through crafted Word documents, and CVE-2025-8088, a WinRAR path traversal zero-day used in July 2025 spearphishing campaigns. GTIG reporting in the content also states that CIGAR/UNC4895, publicly reported as RomCom, exploited CVE-2024-9680 and CVE-2024-49039 as zero-days in 2024. The content further notes this was at least the third time RomCom had been observed exploiting a significant zero-day in the wild. RomCom distributes malware through trojanized legitimate software and fake software updates. Software named in the content includes Adobe products, Advanced IP Scanner, SolarWinds Network Performance Monitor, SolarWinds Orion, KeePass, and Signal. Delivery via SocGholish operated by TA569 is also described. Malware and tooling associated with RomCom in the content include the RomCom backdoor/RAT, Mythic agent, SnipBot, RustyClaw, and fake OneDrive loaders. Successful exploitation of CVE-2025-8088 delivered a SnipBot variant, RustyClaw, and the Mythic agent. The RomCom backdoor is described as capable of executing commands and downloading additional modules, and one reference notes use of HTTPS for command-and-control. The content also links the group to Underground ransomware, likely spread by RomCom, and notes use of Industrial Spy ransomware in financially motivated attacks. The content also includes reporting on overlaps between RomCom-related aliases and Cuba ransomware activity. Tropical Scorpius/UNC2596 is described in one cited report as linked to the Cuba attackers and use of BURNTCIGAR and signed drivers to terminate security products. Mandiant reporting in the content attributes COLDDRAW/Cuba ransomware intrusions to UNC2596. GTIG reporting separately describes CIGAR/UNC4895, also known as RomCom, as a Russian threat group conducting both financially motivated and espionage operations.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Military
- Telecommunication Services
- Financial Services
Where they target
Geographies tied to known operations.
- 🇱🇹 Lithuania
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
24 malware families attributed to this actor across reporting.
19 additional families tracked in Mallory.
Associated vulnerabilities
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
Historical parallels, such as the exploitation of CVE-2023-36884 by Storm-0978, underscore how Office-based RCE vulnerabilities have been weaponized for targeted intrusions.
ESET researchers have discovered a previously unknown zero-day vulnerability in WinRAR being exploited in the wild by Russia-aligned group RomCom... now assigned CVE-2025-8088: a path traversal vulnerability, made possible with the use of alternate data streams.
GTIG spotlighted CIGAR (UNC4895/RomCom) deploying a zero-day chain against Firefox and Windows (CVE-2024-49039) that escalated privileges from low integrity to SYSTEM via Windows RPC abuse, enabling creation/execution of scheduled tasks as SYSTEM.
"Attackers were observed chaining this vulnerability with a remote code execution flaw in Firefox, identified as CVE-2024-9680."
Next the threat actors attempted to use a file called zero.exe, which is used to exploit the Zerologon vulnerability to escalate privileges.
3 more CVEs tied to this actor tracked in Mallory.
Observables
41 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with exploitation of WinRAR vulnerabilities in 2025 campaigns.
Russian cybercriminal group cited as part of a partnership model with Russian intelligence-linked ecosystems and other criminal groups.
Threat actor associated with RomCom operations; observed using SocGholish fake-update JavaScript loader to deliver Mythic Agent payloads.
Conducts dual-use (financial + espionage) operations leveraging CVE-2025-8088 in WinRAR via spearphishing to target Ukrainian military units; delivers NESTPACKER/Snipbot.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.