MeltingClaw

First seen
2022-05-15 00:00:00
Malware type
rat
Profile updated
2026-07-07 13:04:55

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:us country_code:ru

Context

MeltingClaw is a remote access trojan primarily used for cyber espionage targeting government and defense sectors. It allows attackers to gain unauthorized access to systems and extract sensitive information.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Meltingclaw_Auto (yara-rule)

Reports & references

  • Cisco Talos — Uat 5647 Romcom (report)
  • proofpoint.com — 10 Things I Hate About Attribution Romcom Vs Transferloader (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Meltingclaw (report)
  • blog.barracuda.com — Malware Brief Foursome Working Together (report)
  • ncsc.gov.uk — Ncsc Mar Damascened Peacock (report)

External references