Skip to main content
Mallory
MalwareUsed by 2 actors

RomCom RAT

RomCom RAT is a remote access trojan deployed since at least mid-2022 and associated with the threat actor commonly tracked as RomCom, also known as Storm-0978, Tropical Scorpius, UAC-0180, UNC2596, Void Rabisu, and by Google as CIGAR. Reporting also links RomCom RAT activity to the Russian-speaking group Nebulous Mantis. The malware is actively maintained and supports command execution and downloading additional modules. Documented capabilities include encrypted C2 communications, execution of more than 40 remote commands via a dedicated operator panel, browser-data theft through additional modules, credential harvesting, system reconnaissance, Active Directory enumeration, lateral movement, and collection of files, credentials, configuration details, and Microsoft Outlook backups. Persistence has been established through Windows Registry manipulation and COM hijacking, and operators have used living-off-the-land techniques and frequently changing infrastructure hosted via bulletproof providers such as LuxHost and Aeza. RomCom infections have been delivered through spear-phishing emails with weaponized document links, and earlier related campaigns used the Hancitor loader. A described multi-stage chain includes a first-stage DLL that contacts C2, retrieves additional payloads including via IPFS hosted on attacker-controlled domains, executes commands, and launches a final-stage C++ implant. RomCom RAT has also been deployed through exploitation chains: Google and ESET reported Firefox and Tor browser exploitation using CVE-2024-9680 together with CVE-2024-49039 to escape the Firefox sandbox and install the malware with elevated privileges; ESET also described a fake-site chain involving economistjournal[.]cloud redirecting to redjournal[.]cloud that resulted in RomCom RAT installation. Most victims identified in that campaign were in Europe and North America. Reported targeting linked to the associated actor includes critical infrastructure, government agencies, political leaders, and NATO-related defense organizations.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
TA829

"Proofpoint Links RomCom RAT Hackers to New TransferLoader Malware Activity" ... "TA829, the threat group behind RomCom RAT"

via bank info securitybankinfosecurity.com
Nebulous Mantis

"...Nebulous Mantis that has deployed a remote access trojan called RomCom RAT since mid-2022."

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

17 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence1

"Since mid-2022, they’ve deployed RomCom via spear-phishing for espionage, lateral movement, and data theft."

T1566.002Spearphishing LinkEvidence1

"Attack chains mounted by the group typically involve the use of spear-phishing emails with weaponized document links to distribute RomCom RAT."

Persistence

2 techniques
T1546.015Component Object Model HijackingEvidence1

"...set up persistence using COM hijacking..."

T1547.001Registry Run Keys / Startup FolderEvidence2

"RomCom, besides manipulating Windows Registry to set up persistence using COM hijacking..."

T1546.015Component Object Model HijackingEvidence1

"...set up persistence using COM hijacking..."

T1547.001Registry Run Keys / Startup FolderEvidence2

"RomCom, besides manipulating Windows Registry to set up persistence using COM hijacking..."

Stealth

2 techniques
T1036MasqueradingEvidence1
TacticStealth

"Nebulous Mantis imitates trusted services like OneDrive to trick victims into downloading infected files, often hosted on Mediafire."

T1497Virtualization/Sandbox EvasionEvidence1

"Post-infection, a fake PDF triggers an EXE that checks for sandbox evasion markers before downloading further payloads..."

T1555Credentials from Password StoresEvidence1

"Nebulous Mantis uses RomCom malware for stealthy attacks involving system profiling, credential harvesting, and AD/domain enumeration."

Discovery

4 techniques
T1018Remote System DiscoveryEvidence1
TacticDiscovery

"...enumerate Active Directory..."

T1082System Information DiscoveryEvidence2
TacticDiscovery

"The threat actor executes tzutil command to identify the system's configured time zone."

T1482Domain Trust DiscoveryEvidence1
TacticDiscovery

"...credential harvesting, and AD/domain enumeration."

T1497Virtualization/Sandbox EvasionEvidence1

"Post-infection, a fake PDF triggers an EXE that checks for sandbox evasion markers before downloading further payloads..."

Collection

2 techniques
T1005Data from Local SystemEvidence1

"...collect data of interest, including files, credentials, configuration details, and Microsoft Outlook backups."

T1560.001Archive via UtilityEvidence1

"Tools like WinRAR and Plink are deployed, with data exfiltrated from c:\users\public\music."

T1105Ingress Tool TransferEvidence2

"The first-stage RomCom DLL is designed to connect to a C2 server and download additional payloads using the InterPlanetary File System (IPFS)..."

T1568Dynamic ResolutionEvidence1

"The Nebulous Mantis team, which changes the domains they use every month..."

T1572Protocol TunnelingEvidence1

"The attackers used reverse SSH tunnels to ensure persistence."

T1573Encrypted ChannelEvidence1

"The RAT supports advanced evasion techniques, including living-off-the-land (LOTL) tactics and encrypted command and control (C2) communications."

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

"...gathers all critical information from the victim machine and uploads it to their C2 servers."

INDICATORS OF COMPROMISE

IOCs tracked for this family

2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
2 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app1 year ago
domain●●●●●●●●●●●●View more in app2 years ago
ACTIVITY FEED

Recent activity

7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching2

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping17

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.