RomCom is a Windows remote access trojan and backdoor family operated by the Russia-aligned threat actor commonly tracked as Storm-0978, UNC2596, Tropical Scorpius, and Void Rabisu. Initially associated with cybercriminal activity and ransomware-linked operations, it evolved into a dual-use intrusion platform employed for espionage, credential-focused targeting, data theft, and follow-on ransomware deployment against organizations linked to Ukraine and other targets in Europe and North America. Reported victim sectors include government, defense, telecommunications, finance, energy, logistics, manufacturing, healthcare, and other critical infrastructure.
RomCom has been delivered through multiple intrusion vectors. Observed distribution methods include spearphishing emails with malicious documents, weaponized archive attachments, trojanized installers masquerading as legitimate software, fake browser or software update chains, malvertising-driven exploit delivery, and compromised or attacker-controlled landing pages. Campaigns exploiting CVE-2023-36884 in Microsoft Office and Windows and CVE-2025-8088 in WinRAR have been linked to RomCom delivery, and the malware family has also been associated with campaigns using browser and Windows zero-days.
The malware family supports persistent remote access and modular post-compromise activity. Documented capabilities include command execution, host profiling, file and directory discovery, process enumeration, file upload and download, targeted document collection, exfiltration, and retrieval of additional payloads. RomCom variants and related components have used encrypted communications over HTTPS, anti-analysis checks, string and API obfuscation, in-memory execution, COM hijacking, registry-stored encrypted payloads, scheduled-task persistence, and selective execution logic tied to victim characteristics. Later variants such as SnipBot expanded the family with multi-stage loaders, anti-sandboxing, proxy and tunneling functions, and hands-on-keyboard support for internal reconnaissance and data theft.
RomCom has repeatedly appeared in operations that blend criminal and state-aligned tradecraft. Reporting links the operators to ransomware and extortion activity, including use of ransomware closely related to Industrial Spy and Underground, while separate campaigns focused on intelligence collection and targeted intrusions. The family has also been observed in highly selective operations using victim verification and tailored lures, underscoring its role as a mature access platform for both espionage and financially motivated objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft Threat Intelligece has identified threat actors abusing a recently disclosed vulnerability, CVE-2023-36884, in phishing campaigns containing malicious Word documents against government entities in Europe and North America. | Storm-0978, also known as RomCom is a Russian threat actor known for ransomware, espionage operations, and targeted credential-gathering campaigns. Their latest campaign was last detected in June 2023 involving abuse of CVE-2023-36884 to deliver backdoors over phishing emails according to Microsoft Threat Intelligence.
Later that same year, a Russian hacking group exploited a WinRAR vulnerability tracked as CVE-2025-8088 via phishing attacks to install the RomCom malware.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Consequently, it remains unclear whether the actors intended to deploy the ROMCOM backdoor or any related malware associated with Void Rabisu.
Proofpoint released “10 Things I Hate about Attribution: RomCom vs. TransferLoader” detailing connections between RomCom and TransferLoader.
"RomCom malware used the SocGholish fake update loader to deliver Mythic Agent to a U.S. civil engineering firm."
...Void Rabisu APT group is using a remote access trojan called RomCom that uses HTTPS for C&C communications
"...the group’s primary weapon of choice is the RomCom remote access trojan (RAT)—a versatile tool enabling both data exfiltration and ransomware deployment."
29 distinct techniques documented for this family, organized by ATT&CK tactic.
We discovered that 27 domains—24 for TransferLoader and three for RomCom—were deemed likely to turn malicious upon registration.
Microsoft is warning about a phishing campaign from the threat actor known as RomCom that is targeting the defense industry and government entities in Europe and North America.
“they also utilize binary padding techniques… (we've seen a file with 1.7 gigabytes)” / “null bytes are appended to the file…”
“RomCom 3.0 binaries are protected with VMProtect.” / “RomCom uses VMProtect”
This story includes detections for changes to 'ChannelAccess' and 'CustomSD' registry values, as well as the use of tools like 'sc.exe sdset', 'icacls' and 'subinacl' to modify securable objects (files, registry, services, etc) permissions.
“performs detailed network and domain discovery using tools like: netstat, nltest, arp, ping, and PowerShell-based port scans.”
“RomCom 3.0 commands are received as responses to HTTP POST requests…” / “RomCom uses HTTPS for C&C communications”
“After the first-stage downloader is triggered, the malware connects to a command-and-control domain (e.g., drivedefend.com) and pulls down additional payloads, including a Keyprov.dll backdoor.”
“Run AnyDesk on the victim’s machine… send the AnyDesk ID to the C&C server” / “download the AnyDesk executable…”
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor associated with Void Rabisu; the report notes it has undergone multiple enhancements and is considered an advanced piece of malware.
RomCom is mentioned as malware installed through exploitation of a WinRAR vulnerability in phishing attacks by a Russian hacking group.
Backdoor malware delivered via malicious RAR archives exploiting CVE-2025-8088 to gain initial access and execute code (e.g., by placing executables in Windows Startup folders).
Loader/backdoor malware used in spear-phishing campaigns, associated with espionage and financial crime operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.