ROMCOM RAT

Aliases: PEAPOD, SingleCamper, SnipBot

First seen
2022-09-01 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 13:04:49

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical energy-and-utilities

Targeted regions: country_code:us country_code:uk country_code:ca

Context

Unit 42 observed threat actor Tropical Scorpius using this RAT in operations where also Cuba ransomware was deployed.

Used by threat actors

Reports & references

  • blogs.blackberry.com — Romcom Spoofing Solarwinds Keepass (report)
  • blogs.blackberry.com — Unattributed Romcom Threat Actor Spoofing Popular Apps Now Hits Ukrainian Militaries (report)
  • labs.k7computing.com — Romcom Rat Not Your Typical Love Story (report)
  • Trend Micro — Void Rabisu S Use Of Romcom Backdoor Shows A Growing Shift In Th (report)
  • Cisco Talos — Uat 5647 Romcom (report)
  • Trend Micro — Shadow Void 042 (report)
  • blog.google — Ukraine Remains Russias Biggest Cyber Focus In 2023 (report)
  • Palo Alto Unit 42 — Cuba Ransomware Tropical Scorpius (report)
  • blog.barracuda.com — Malware Brief Foursome Working Together (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Romcom Rat (report)
  • CERT-UA — 3349703 (report)
  • circleid.com — Romcom And Transferloader Iocs In The Spotlight (report)
  • Palo Alto Unit 42 — Snipbot Romcom Malware Variant (report)
  • blogs.blackberry.com — Romcom Targets Ukraine Nato Membership Talks At Nato Summit (report)
  • Microsoft — Storm 0978 Attacks Reveal Financial And Espionage Motives (report)

External references