Skip to main content
Mallory
7 malware families

TA829

Also known asta829

TA829 is a Russia-linked, Russia-aligned threat actor also tracked as Nebulous Mantis, Storm-0978, and UNC2596. Reporting cited in the source material associates TA829 with the RomCom RAT and describes the group as conducting both espionage and financial attacks. The content also states the actor has exploited zero-days in Firefox and Windows. Recent reporting describes strong tactical and infrastructure overlap between TA829 and the threat cluster UNK_GreenSec. Shared tradecraft includes use of REM proxy services to relay traffic to newly created freemail accounts, establishment of SSH tunnels using PuTTY's PLINK utility, and use of IPFS services to host utilities. Researchers assess that TA829 and UNK_GreenSec may share a third-party infrastructure provider or may be the same operation. In the activity described, TA829 intrusions involved the MeltingClaw and RustyClaw downloaders, which delivered the ShadyHammock, DustyHammock, and SingleCamper backdoors. The source material links TA829 to ongoing malware campaigns and notes broader overlap between cybercrime and espionage activity in this cluster.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal7

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.