SHADOW-VOID-042 is a temporary intrusion-set designation for a highly targeted spear-phishing cluster active in late 2025 and associated with campaigns against critical infrastructure and technology-sector organizations. The group is known for a November 2025 operation that impersonated Trend Micro in phishing lures and decoy web content to target organizations in the defense, energy, chemical, cybersecurity, and information and communications technology sectors, including Trend Micro and a subsidiary. The same cluster was also linked to an October 2025 campaign that used HR- and complaint-themed lures aimed at executives and human resources personnel. The actor’s tradecraft combines tailored social engineering with staged exploitation. Observed activity included phishing emails framed as urgent security advisories, redirection through fake browser-security interstitials, and JavaScript-based exploit delivery. Researchers recovered exploitation for CVE-2018-6065 and assessed that payload delivery was customized per target, with indications that more advanced exploits may have been selectively used against higher-value victims. Because the attacks were disrupted early, the final payload was not observed. SHADOW-VOID-042 shows significant tactical overlap with Void Rabisu, also widely tracked as RomCom or Storm-0978, a Russian-aligned hybrid threat actor, but a definitive attribution has not been established. As a result, SHADOW-VOID-042 is tracked separately pending stronger linkage. High-confidence observed behaviors support phishing-led initial access, reconnaissance and victim tailoring, and defense-evasion through impersonation of trusted brands and staged delivery infrastructure. The campaign profile is consistent with espionage-oriented targeting of strategically significant sectors rather than broad opportunistic crime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SHADOW-VOID-042 is responsible for a spear-phishing campaign using Trend Micro-themed lures, exploiting a Chrome vulnerability and delivering multi-stage payloads, with overlaps to RomCom/Void Rabisu activity.
SHADOW-VOID-042 conducted a sophisticated spear-phishing campaign impersonating Trend Micro to breach defense, energy, and chemical organizations, as well as Trend Micro itself. The campaign used tailored phishing emails and decoy websites, leveraging both old and likely new browser exploits, and is linked to previous operations using different social engineering lures.
Temporary intrusion set designation for campaigns using Trend Micro-themed spear-phishing/decoy sites and multi-stage tailored delivery; suspected (but unconfirmed) linkage to Void Rabisu.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.