ROMCOM RAT
Aliases: PEAPOD, SingleCamper, SnipBot
- First seen
- 2022-09-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Profile updated
- 2026-07-07 13:04:49
Targeted industries: government-and-public-sector healthcare-and-pharmaceutical energy-and-utilities
Targeted regions: country_code:us country_code:uk country_code:ca
Context
Unit 42 observed threat actor Tropical Scorpius using this RAT in operations where also Cuba ransomware was deployed.
Used by threat actors
- Void Rabisu (threat-actor)
Reports & references
- blogs.blackberry.com — Romcom Spoofing Solarwinds Keepass (report)
- blogs.blackberry.com — Unattributed Romcom Threat Actor Spoofing Popular Apps Now Hits Ukrainian Militaries (report)
- labs.k7computing.com — Romcom Rat Not Your Typical Love Story (report)
- Trend Micro — Void Rabisu S Use Of Romcom Backdoor Shows A Growing Shift In Th (report)
- Cisco Talos — Uat 5647 Romcom (report)
- Trend Micro — Shadow Void 042 (report)
- blog.google — Ukraine Remains Russias Biggest Cyber Focus In 2023 (report)
- Palo Alto Unit 42 — Cuba Ransomware Tropical Scorpius (report)
- blog.barracuda.com — Malware Brief Foursome Working Together (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Romcom Rat (report)
- CERT-UA — 3349703 (report)
- circleid.com — Romcom And Transferloader Iocs In The Spotlight (report)
- Palo Alto Unit 42 — Snipbot Romcom Malware Variant (report)
- blogs.blackberry.com — Romcom Targets Ukraine Nato Membership Talks At Nato Summit (report)
- Microsoft — Storm 0978 Attacks Reveal Financial And Espionage Motives (report)