RomCom is a Windows remote access trojan and backdoor family associated with the Russia-aligned threat cluster tracked as Storm-0978, Tropical Scorpius, Void Rabisu, and UNC2596. First observed in 2022, it evolved from activity linked to financially motivated operations into a tool used in both cybercrime and espionage campaigns, particularly against organizations connected to Ukraine as well as targets in Europe and North America. Reported victim sectors include government, defense, telecommunications, finance, manufacturing, logistics, health, digital services, and critical infrastructure-related organizations.
RomCom has been delivered through multiple intrusion vectors. Early campaigns used phishing and spearphishing emails with malicious documents or archives. Operators also distributed trojanized installers for widely used legitimate software, and later campaigns used fake browser-update infrastructure associated with SocGholish. The malware has also been deployed through exploitation of major client-side vulnerabilities, including CVE-2023-36884 in Microsoft Office and Windows HTML handling, CVE-2024-9680 chained with CVE-2024-49039 in Firefox and Windows, and CVE-2025-8088 in WinRAR. In WinRAR exploitation campaigns, weaponized archives were used to establish persistence and launch RomCom-related payloads after user interaction.
The malware family supports remote command execution, host profiling, file and directory discovery, process enumeration, payload retrieval, and data theft. Documented variants and related components have supported targeted document collection and exfiltration, proxying and tunneling, and delivery of follow-on tooling including Mythic agents and ransomware. Later iterations such as SnipBot introduced multi-stage execution, anti-analysis checks, encrypted strings and configuration data, registry-stored payloads, and COM hijacking to load malicious components into trusted processes. RomCom operators have also been observed conducting hands-on-keyboard post-compromise activity, internal network discovery, and use of legitimate administrative tools for staging and transfer of collected data.
Operational reporting consistently links RomCom to campaigns with dual financial and intelligence objectives. The associated actor has conducted ransomware and extortion activity while also running targeted credential-gathering and espionage-oriented intrusions. RomCom intrusions have been tied to lateral movement and broader post-exploitation activity, and the malware has served as a primary access and control mechanism in operations aligned with Russian strategic interests.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Later that same year, a Russian hacking group exploited a WinRAR vulnerability tracked as CVE-2025-8088 via phishing attacks to install the RomCom malware.
RomCom is abusing a zero-day vulnerability, CVE-2023-36884, involving specially crafted Microsoft Word documents. | The threat actor uses trojanized versions of popular software — including products from Adobe, Advanced IP Scanner, SolarWinds Network Performance Monitor, SolarWinds Orion, KeePass and Signal — to install RomCom backdoors.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The threat actor uses trojanized versions of popular software — including products from Adobe, Advanced IP Scanner, SolarWinds Network Performance Monitor, SolarWinds Orion, KeePass and Signal — to install RomCom backdoors.
"RomCom malware used the SocGholish fake update loader to deliver Mythic Agent to a U.S. civil engineering firm."
...Void Rabisu APT group is using a remote access trojan called RomCom that uses HTTPS for C&C communications
"...the group’s primary weapon of choice is the RomCom remote access trojan (RAT)—a versatile tool enabling both data exfiltration and ransomware deployment."
...tactical similarities between the threat actors behind the RomCom RAT and a cluster ... delivering a loader dubbed TransferLoader.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Microsoft is warning about a phishing campaign from the threat actor known as RomCom that is targeting the defense industry and government entities in Europe and North America.
“they also utilize binary padding techniques… (we've seen a file with 1.7 gigabytes)” / “null bytes are appended to the file…”
“RomCom 3.0 binaries are protected with VMProtect.” / “RomCom uses VMProtect”
This story includes detections for changes to 'ChannelAccess' and 'CustomSD' registry values, as well as the use of tools like 'sc.exe sdset', 'icacls' and 'subinacl' to modify securable objects (files, registry, services, etc) permissions.
“performs detailed network and domain discovery using tools like: netstat, nltest, arp, ping, and PowerShell-based port scans.”
“RomCom 3.0 commands are received as responses to HTTP POST requests…” / “RomCom uses HTTPS for C&C communications”
“After the first-stage downloader is triggered, the malware connects to a command-and-control domain (e.g., drivedefend.com) and pulls down additional payloads, including a Keyprov.dll backdoor.”
“Run AnyDesk on the victim’s machine… send the AnyDesk ID to the C&C server” / “download the AnyDesk executable…”
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RomCom is mentioned as malware installed through exploitation of a WinRAR vulnerability in phishing attacks by a Russian hacking group.
Backdoor malware delivered via malicious RAR archives exploiting CVE-2025-8088 to gain initial access and execute code (e.g., by placing executables in Windows Startup folders).
Loader/backdoor malware used in spear-phishing campaigns, associated with espionage and financial crime operations.
ROMCOM is a backdoor malware typically associated with the Void Rabisu threat group, known for cybercrime and espionage activities aligned with Russian interests. It is often deployed as a final payload in targeted spear-phishing campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.