SlipScreen is a first-stage Windows loader associated with RomCom operations, particularly activity tracked as TA829. It is used after initial compromise to deepen access and stage follow-on payloads, including additional loaders, backdoors, remote-access tooling, and in some cases ransomware. The malware has been observed as part of RomCom intrusion chains in which an earlier foothold is followed by deployment of SlipScreen to execute later-stage components in memory while minimizing forensic visibility.
SlipScreen has been reported in both Rust and C++ variants and is commonly disguised as a benign document-related application, including use of a PDF reader icon and deceptive signing intended to increase execution likelihood and reduce suspicion. Its operators have used social-engineering lures consistent with RomCom tradecraft, including spearphishing themes such as job applications and document-sharing notifications, and executables masquerading as documents or document viewers.
A defining characteristic of SlipScreen is its emphasis on evasion. Reported variants perform environmental checks intended to avoid sandbox execution, including validation of recent-document activity on the host before proceeding. The malware decrypts and executes shellcode in memory, reducing reliance on overt on-disk payloads. Persistence has been associated with COM hijacking, enabling the loader to survive reboots while blending with normal Windows component behavior.
SlipScreen is part of a broader RomCom ecosystem that has targeted government, defense, logistics, manufacturing, financial, and other organizations, with earlier activity heavily focused on Ukraine and Poland and later campaigns expanding across Europe and North America. Within TA829 operations, SlipScreen functions as a stealthy staging component that supports both espionage-oriented intrusions and financially motivated attacks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...deploy distinct payloads: TransferLoader for UNK_GreenSec and SlipScreen for TA829."
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A first-stage loader (Rust/C++) used to validate user activity (RecentDocs registry checks) for sandbox evasion, decrypt and execute shellcode in-memory, establish C2, and maintain persistence via COM hijacking so it re-triggers with explorer.exe restarts.
Stealthy loader used after RomCom RAT compromise to load ransomware into target systems.
A distinct malware payload associated with TA829 campaigns that share infrastructure and phishing tradecraft with TransferLoader activity.
SlipScreen is a first-stage loader used by TA829 to initiate infection chains. It decrypts and loads shellcode into memory, performs registry checks to evade sandboxes, and downloads further payloads such as RustyClaw or MeltingClaw, leading to backdoors like DustyHammock or SingleCamper.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.