Bridewell identified Operation Deceptive Prospect, a phishing campaign targeting two UK organisations in retail/hospitality and critical national infrastructure through customer feedback portals. Discovered in March 2025, the campaign used complaint and recruitment lures to direct customer service staff through cloud-storage impersonation domains and multiple redirects to a Windows executable disguised as a PDF. The executable carried a likely stolen or compromised signing certificate. Researchers identified 97 potentially associated first-stage domains, dedicated payload-hosting infrastructure and related executable samples. Bridewell assessed significant technical overlap with RomCom with high confidence, but its malware analysis did not independently establish definitive attribution. Sandbox testing showed no overt malicious activity; suspected anti-sandbox checks and broader geographic targeting remained unconfirmed.
The campaign follows ESET’s discovery of a separate RomCom operation chaining CVE-2024-9680, a use-after-free vulnerability affecting Firefox, Thunderbird and Tor Browser, with CVE-2024-49039, a Windows privilege-escalation flaw. That chain allowed attackers to install the RomCom backdoor without further user interaction after victims reached malicious web infrastructure. The Russia-aligned group targeted sectors including government, defense, energy and legal services, with capabilities supporting data theft, credential harvesting, lateral movement and persistence. Mozilla and Microsoft issued fixes following coordinated disclosure. Organisations should verify deployment of those patches, scrutinise links submitted through public-facing customer portals, and avoid treating a valid digital signature as proof that a downloaded file is safe.

See which actors are running it and whether you're in range.
14 events from the most recent confirmed update back to the earliest known activity.
The principal executable carried an April 16, 2025 compilation timestamp and was signed that day with a certificate identifying GMC CONSTRUCTION AND TRADING COMPANY LIMITED. Bridewell assessed the certificate as likely stolen or compromised.
GMC CONSTRUCTION AND TRADING COMPANY LIMITED, the apparently UK-based company identified in the principal payload's signing certificate, was dissolved the day before the sample was signed.
Bridewell identified Operation Deceptive Prospect targeting two UK customers in retail/hospitality and critical national infrastructure. Attackers submitted complaint and recruitment lures through customer feedback portals, directing customer service staff through cloud-storage impersonation pages to executable downloads disguised as PDF evidence.
Microsoft patched CVE-2024-49039, the Windows Task Scheduler vulnerability used in RomCom's exploit chain. The updated WPTaskScheduler.dll restricted access to the RPC interface used for privilege escalation.
ESET reported exploit-chain activity from October 10 through November 4, 2024, using fake websites to redirect visitors to exploit servers. The Firefox and Windows vulnerabilities enabled installation of the RomCom backdoor without further user interaction, primarily affecting targets in Europe and North America.
Mozilla released a patch for the Firefox use-after-free vulnerability exploited by RomCom. ESET reported that Mozilla and the Tor Project released fixes within 25 hours of disclosure.
RomCom's 2024 espionage targets included Ukrainian government, defense, and energy organizations, US pharmaceutical and insurance organizations, Germany's legal sector, and other European governmental bodies.
Bridewell reported tracking activity associated with the subsequently identified Operation Deceptive Prospect campaign since 2024.
Samples of SnipBot, described as RomCom 5.0, date to December 2023. The variant added obfuscation, anti-sandbox techniques, targeted exfiltration, signed downloaders, and COM-hijacking persistence.
RomCom exploited Microsoft Word vulnerability CVE-2023-36884 as part of its historical operations.
The RomCom 4.0 backdoor variant, also known as PEAPOD, appeared in late 2023.
Bridewell identified 97 potentially associated first-stage domains and dedicated payload-hosting infrastructure, and published campaign indicators plus KQL and YARA detection content. It assessed significant technical overlap with RomCom with high confidence, while noting that sandbox execution showed no overt malicious activity and its malware analysis did not independently establish definitive attribution.
ESET published technical details, indicators of compromise, and malware samples for the campaign. Its analysis described reflective DLL injection shellcode and a sandbox escape through an undocumented Windows RPC endpoint.
ESET researchers discovered CVE-2024-9680, a use-after-free vulnerability affecting Firefox, Thunderbird, and Tor Browser, being exploited by RomCom. The attack chained it with Windows Task Scheduler vulnerability CVE-2024-49039 to escape the browser sandbox.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 56 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
bridewell.com
Open sourcewelivesecurity.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.