SingleCamper is a backdoor used by the Russia-linked TA829 cluster, also tracked as Nebulous Mantis, Storm-0978, and UNC2596, in campaigns that Proofpoint associated with both espionage- and cybercrime-aligned activity. It is delivered in TA829 intrusion chains by the RustyClaw and MeltingClaw downloaders/loaders, alongside other TA829 malware including ShadyHammock and DustyHammock. Proofpoint reported that in April 2025 TA829 shifted to using the ShadyHammock and SingleCamper tool suite in financially motivated campaigns.
SingleCamper functions as a main foothold on compromised hosts. Reporting cited in the content states that it has an extensive command set available from command-and-control and is used to further compromise victim networks by issuing reconnaissance commands and downloading additional tooling, including from InterPlanetary File System (IPFS) services. Proofpoint assessed that DustyHammock and SingleCamper likely can be administered from the same panel because their beacon structures are highly similar.
Behaviorally, SingleCamper derives encryption key material from host-specific WMI values including ProcessorID and Serial Number, sets the mutex Global\srvmutex, and uses a beacon-and-sleep loop to communicate with its C2 server. The content does not provide additional confirmed indicators beyond the mutex value. The malware was discussed in the context of TA829 campaigns that used overlapping infrastructure and tradecraft with a separate cluster tracked as UNK_GreenSec, including REM proxy services on compromised MikroTik routers, PuTTY PLINK SSH tunnels, and IPFS-hosted utilities, but SingleCamper itself is specifically attributed in the provided content to TA829.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...downloaders that deliver the ShadyHammock, DustyHammock, and SingleCamper backdoors.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor delivered by MeltingClaw/RustyClaw in TA829 intrusions.
SingleCamper is a backdoor used by TA829 for persistent access, reconnaissance, and further compromise. It supports a wide range of commands and is used in both espionage and financially-motivated campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.