TA829 is a Russia-aligned hybrid threat actor known for intelligence and financial attacks using RomCom RAT and SlipScreen.
Analyst brief
TA829 is a Russia-aligned hybrid threat actor conducting both intelligence-gathering and financially motivated attacks. The group exploits zero-day vulnerabilities in Mozilla Firefox and Microsoft Windows, deploying RomCom RAT and a specific strain called SlipScreen on victim systems. To disguise its origin, TA829 leverages REM Proxy services hosted on compromised MikroTik routers. Defenders should monitor for phishing campaigns delivering these payloads and investigate unusual outbound connections, as the actor's TTPs closely mirror those of UNK_GreenSec.
TA829
unknown
TA829 is a Russia-aligned threat actor that employs the RomCom RAT for intelligence-gathering and financially motivated cyberattacks, exploiting zero-day vulnerabilities in Mozilla Firefox and Microsoft Windows. The group utilizes REM Proxy services hosted on compromised MikroTik routers to relay traffic and disguise its origin. In their operations, victims targeted by TA829 receive a strain known as SlipScreen, while their infrastructure and tactics show significant similarities to those of UNK_GreenSec. TA829's hybrid approach combines espionage with financial fraud, making it a notable player in the cyber threat landscape.