Proofpoint reported that activity tied to TA829 and a separate cluster it tracks as UNK_GreenSec used overlapping phishing infrastructure and social-engineering lures, even as the two operations delivered different malware. TA829 continued deploying its established RomCom-related toolset — including SlipScreen, RustyClaw, MeltingClaw, DustyHammock, ShadyHammock, and SingleCamper — while UNK_GreenSec used the newer TransferLoader, which researchers linked to Metasploit and Morpheus ransomware. Both clusters abused compromised MikroTik routers as REM Proxy nodes, used freemail senders and Rebrandly redirects, and relied on landing pages themed around OneDrive or Google Drive.
A follow-on infrastructure review of 109 domains found additional overlap between the RomCom and TransferLoader ecosystems, including four TransferLoader IoC domains appearing across five typosquatting groups and shared registrar, registrant-country, nameserver, and IP patterns. Researchers said many domains were registered shortly before use, while 27 of 109 had already been flagged as likely malicious 77 to 271 days before they were later published as IoCs. The broader artifact set also included thousands of email- and string-linked domains, dozens of related malicious domains and IPs, and recurring use of Tucows and U.S.-based registrations, reinforcing evidence of a meaningful operational relationship without conclusively proving the two clusters are the same actor.

TTPs, infrastructure, and targeting history in one profile.
14 events from the most recent confirmed update back to the earliest known activity.
On 30 June 2025, Proofpoint published "10 Things I Hate About Attribution: RomCom vs. TransferLoader," concluding there was likely some relationship between TA829 and UNK_GreenSec but insufficient evidence to determine the exact linkage.
WhoisXML API reported that livestorage[.]click appeared in a seven-domain typosquatting group created on 15 April 2025.
In April 2025, Proofpoint observed TA829 shift to using the ShadyHammock and SingleCamper tool suite in financially motivated campaigns.
Proofpoint said UNK_GreenSec used more advanced filtering before TA829 later adopted similar filtering practices in March 2025.
WhoisXML API found that dr365[.]live appeared in a four-domain typosquatting group created on 21 February 2025.
WhoisXML API reported that 1drive[.]expert appeared in a six-domain typosquatting group created on 14 February 2025. The group used Tucows, Alibaba, and Shanghai Fuhu Information Technology as registrars and multiple DNS providers.
Proofpoint observed UNK_GreenSec conduct four TransferLoader campaigns in the first two weeks of February 2025 targeting North America.
During February 2025, Proofpoint observed highly similar email campaigns and redirection infrastructure used by TA829 and UNK_GreenSec. It initially clustered the activity with TA829 before later separating it based on infection-chain and malware differences.
Proofpoint reported that TA829 resumed operations in February 2025, returning to campaigns that used plaintext phishing emails, freemail senders, and spoofed cloud-storage links.
WhoisXML API found that all 20 RomCom IoC domains were created in 2025 between 20 January 2025 and 11 June 2025, with the first observed creation date on 20 January 2025.
WhoisXML API found that the 89 TransferLoader IoC domains were created between 2 October 2024 and 14 April 2025, marking the start of the observed domain-registration window for that cluster.
Proofpoint said TA829 resumed operations in February 2025 after it was last observed in October 2024, establishing October 2024 as the group's prior known activity before the pause.
Barracuda states that RomCom RAT was first identified in 2022. The malware was initially used primarily against Ukrainian and Polish targets before later being adapted to financial crime activity.
WhoisXML API published analysis of 109 RomCom and TransferLoader IoC domains, highlighting typosquatting-group overlaps and noting that 27 domains had been flagged as likely malicious before they were reported as IoCs.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 32 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
circleid.com
Open sourceblog.barracuda.com
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.