SHADOW-VOID-042 is a temporary intrusion set used to track two related 2025 spear-phishing campaigns that show notable tactical and infrastructure overlap with Void Rabisu, also known as ROMCOM, Tropical Scorpius, and Storm-0978, but lack sufficient evidence for high-confidence attribution to that actor. The cluster conducted targeted operations in October and November 2025 against executives, upper management, and HR personnel in critical and commercially sensitive sectors. The October 2025 activity used tailored social-engineering lures including anonymous workplace-harassment complaints, academic research invitations, and work-related questionnaires. The November 2025 activity used Trend Micro-themed lures, including fake security-update messaging, to target Trend Micro, a subsidiary, a partner, and organizations in defense, energy, chemical, cybersecurity, information and communications technology, logistics, finance, manufacturing, food, retail, and ISP-related environments. Observed tradecraft included spear-phishing, multi-step redirection, impersonation of trusted brands, exploit delivery through browser-based JavaScript, host-specific payload staging, and persistence via scheduled task execution with SYSTEM privileges. Recovered components showed a staged infection chain in which a victim was redirected to a fake browser-security page, JavaScript executed exploit code, shellcode generated a machine-specific identifier, and an encrypted second-stage binary was downloaded and installed. The loader was customized to the victim host and attempted to retrieve an additional payload from command-and-control infrastructure, but the final payload was not recovered. As a result, deployment of the ROMCOM backdoor or another follow-on malware family was not confirmed. The cluster shares several characteristics with activity previously associated with Void Rabisu, including social-engineering-heavy intrusion chains, use of redirection infrastructure, operational security measures, and targeting of strategically relevant sectors. However, direct observation of hallmark Void Rabisu tooling was not established, and the campaigns continue to be tracked separately. Based on the observed victimology and intrusion behavior, SHADOW-VOID-042 is best characterized as a targeted intrusion actor conducting phishing-led initial access and tailored post-exploitation staging against high-value organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Temporary intrusion set behind October and November 2025 spear-phishing and social-engineering campaigns targeting executives and HR personnel across multiple sectors, using browser-exploit delivery, staged loaders, C2 communications, and likely espionage-oriented follow-on activity.
SHADOW-VOID-042 is responsible for a spear-phishing campaign using Trend Micro-themed lures, exploiting a Chrome vulnerability and delivering multi-stage payloads, with overlaps to RomCom/Void Rabisu activity.
SHADOW-VOID-042 conducted a sophisticated spear-phishing campaign impersonating Trend Micro to breach defense, energy, and chemical organizations, as well as Trend Micro itself. The campaign used tailored phishing emails and decoy websites, leveraging both old and likely new browser exploits, and is linked to previous operations using different social engineering lures.
Temporary intrusion set designation for campaigns using Trend Micro-themed spear-phishing/decoy sites and multi-stage tailored delivery; suspected (but unconfirmed) linkage to Void Rabisu.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.