RomCom RAT Targeting NATO and Ukraine Support Groups

Share:

The threat actors behind the RomCom RAT have been suspected of phishing attacks targeting the upcoming NATO Summit in Vilnius as well as an identified organization supporting Ukraine abroad.

The findings come from the BlackBerry Threat Research and Intelligence team, which found two malicious documents submitted from a Hungarian IP address on July 4, 2023.

RomCom, also tracked under the names Tropical Scorpius, UNC2596, and Void Rabisu, was recently observed staging cyber attacks against politicians in Ukraine who are working closely with Western countries and a U.S.-based healthcare organization involved with aiding refugees fleeing the war-torn country.

Attack chains mounted by the group are geopolitically motivated and have employed spear-phishing emails to point victims to cloned websites hosting trojanized versions of popular software. Targets include militaries, food supply chains, and IT companies.

 

The latest lure documents identified by BlackBerry impersonate Ukrainian World Congress, a legitimate non-profit, (“Overview_of_UWCs_UkraineInNATO_campaign.docx“) and feature a bogus letter declaring support for Ukraine’s inclusion to NATO (“Letter_NATO_Summit_Vilnius_2023_ENG(1).docx“).

“Although we haven’t yet uncovered the initial infection vector, the threat actor likely relied on spear-phishing techniques, engaging their victims to click on a specially crafted replica of the Ukrainian World Congress website,” the Canadian company said in an analysis published last week.

Opening the file triggers a sophisticated execution sequence that entails retrieving intermediate payloads from a remote server, which, in turn, exploits Follina (CVE-2022-30190), a now-patched security flaw affecting Microsoft’s Support Diagnostic Tool (MSDT), to achieve remote code execution.

The result is the deployment of RomCom RAT, an executable written in C++ that’s designed to collect information about the compromised system and remote commandeer it.

“Based on the nature of the upcoming NATO Summit and the related lure documents sent out by the threat actor, the intended victims are representatives of Ukraine, foreign organizations, and individuals supporting Ukraine,” BlackBerry said.

“Based on the available information, we have medium to high confidence to conclude that this is a RomCom rebranded operation, or that one or more members of the RomCom threat group are behind this new campaign supporting a new threat group.”

 

(c) The Hacker News

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
9:40 am, Jan 14, 2025
weather icon 5°C
L: 3° | H: 6°
broken clouds
Humidity: 90 %
Pressure: 1035 mb
Wind: 10 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 8:00 am
Sunset: 4:18 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
3° | 6°°C 0 mm 0% 5 mph 97 % 1035 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
6° | 9°°C 0 mm 0% 4 mph 96 % 1035 mb 0 mm/h
Thu Jan 16 9:00 pm
weather icon
6° | 9°°C 0 mm 0% 5 mph 95 % 1034 mb 0 mm/h
Fri Jan 17 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 4 mph 96 % 1035 mb 0 mm/h
Sat Jan 18 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 4 mph 87 % 1033 mb 0 mm/h
Today 12:00 pm
weather icon
5° | 6°°C 0 mm 0% 5 mph 86 % 1035 mb 0 mm/h
Today 3:00 pm
weather icon
6° | 7°°C 0 mm 0% 4 mph 87 % 1034 mb 0 mm/h
Today 6:00 pm
weather icon
7° | 7°°C 0 mm 0% 5 mph 96 % 1034 mb 0 mm/h
Today 9:00 pm
weather icon
7° | 7°°C 0 mm 0% 4 mph 97 % 1035 mb 0 mm/h
Tomorrow 12:00 am
weather icon
8° | 8°°C 0 mm 0% 4 mph 96 % 1035 mb 0 mm/h
Tomorrow 3:00 am
weather icon
7° | 7°°C 0 mm 0% 3 mph 95 % 1034 mb 0 mm/h
Tomorrow 6:00 am
weather icon
6° | 6°°C 0 mm 0% 2 mph 95 % 1034 mb 0 mm/h
Tomorrow 9:00 am
weather icon
6° | 6°°C 0 mm 0% 2 mph 96 % 1035 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€94,091.46
4.00%
Ethereum(ETH)
€3,159.63
2.73%
XRP(XRP)
€2.51
6.18%
Tether(USDT)
€0.98
0.04%
Solana(SOL)
€184.06
5.05%
Dogecoin(DOGE)
€0.340556
8.04%
USDC(USDC)
€0.98
-0.01%
Shiba Inu(SHIB)
€0.000020
4.31%
Pepe(PEPE)
€0.000017
3.81%
Peanut the Squirrel(PNUT)
€0.60
13.06%
Scroll to Top