RomCom
Aliases: Storm-0978, UAT-5647, RomCom, Underground Team
- Origin
- RU
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- team
- Actor type
- nation-state
- Last IoC activity
- 2026-07-22 03:55:48
- Profile updated
- 2026-07-07 11:48:59
Targeted industries: defense-and-aerospace government-and-public-sector
Targeted regions: country_code:ua
Context
ROMCOM is an evolving and sophisticated threat actor group that has been using the malware tool ROMCOM for espionage and financially motivated attacks. They have targeted organizations in Ukraine and NATO countries, including military personnel, government agencies, and political leaders. The ROMCOM backdoor is capable of stealing sensitive information and deploying other malware, showcasing the group's adaptability and growing sophistication.
Reports & references
- bsi.bund.de — Aktive Apt Gruppen Node (report)
- blogs.blackberry.com — Romcom Spoofing Solarwinds Keepass (report)
- blogs.blackberry.com — Unattributed Romcom Threat Actor Spoofing Popular Apps Now Hits Ukrainian Militaries (report)
- Trend Micro — Void Rabisu Targets Female Leaders With New Romcom Variant (report)
- labs.k7computing.com — Romcom Rat Not Your Typical Love Story (report)
- blogs.blackberry.com — Decoding Romcom Behaviors And Opportunities For Detection (report)
- Trend Micro — Void Rabisu S Use Of Romcom Backdoor Shows A Growing Shift In Th (report)
- Cisco Talos — Uat 5647 Romcom (report)
- raw.githubusercontent.com — Microsoftmapping (report)
Attributed from
- Operation Deceptive Prospect (campaign)