RomCom is known for espionage and financially motivated attacks targeting entities in NATO countries.
Analyst brief
RomCom (also tracked as Storm-0978 and UAT-5647) is an evolving threat actor conducting both espionage and financially motivated attacks. They primarily target entities in Germany, alongside military personnel, government agencies, and political leaders in NATO countries. The group uses the ROMCOM backdoor to steal sensitive information and deploy additional malware. Defenders should focus on email-based initial access vectors, monitor for network anomalies, and strengthen endpoint security to detect the backdoor's activity.
RomCom
Storm-0978UAT-5647
unknown
ROMCOM is an evolving and sophisticated threat actor group that has been using the malware tool ROMCOM for espionage and financially motivated attacks. They have targeted organizations in Ukraine and NATO countries, including military personnel, government agencies, and political leaders. The ROMCOM backdoor is capable of stealing sensitive information and deploying other malware, showcasing the group's adaptability and growing sophistication.