Threat Advisory

RomCom Malware Deployment in UAT-5647 Targeted Attacks

Threat: Malware
Threat Actor Name: RomCom
Threat Actor Type: Financially Motivated
Targeted Region: Ukraine, Poland
Alias: Storm-0978, UAT-5647
Targeted Sector: Government & Defense
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

UAT-5647, a Russian-speaking threat actor group also known as RomCom, has been conducting a focused cyber campaign against high-profile Ukrainian government entities and select targets in Poland. Researchers have observed these threat actors deploying a revised version of their RomCom malware, named "SingleCamper," through complex infection chains. UAT-5647’s activity centers on espionage, aiming to gather sensitive data, with a potential for ransomware escalation. This latest variant utilizes a loopback address for stealthy communications, enhancing its evasive capacity. With ongoing geopolitical tensions, the group’s operations exhibit a dual-purpose strategy: data exfiltration for intelligence and, possibly, disruption through financial extortion.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

UAT-5647, a Russian-speaking threat actor group also known as RomCom, has been conducting a focused cyber campaign against high-profile Ukrainian government entities and select targets in Poland. Researchers have observed these threat actors deploying a revised version of their RomCom malware, named "SingleCamper," through complex infection chains. UAT-5647’s activity centers on espionage, aiming to gather sensitive data, with a potential for ransomware escalation. This latest variant utilizes a loopback address for stealthy communications, enhancing its evasive capacity. With ongoing geopolitical tensions, the group’s operations exhibit a dual-purpose strategy: data exfiltration for intelligence and, possibly, disruption through financial extortion.[emaillocker id="1283"]

The infection chain leverages spear-phishing techniques, leading to the deployment of sophisticated downloaders and backdoors. The initial payloads, RustClaw and MeltingClaw, enable persistence on infected systems, with RustClaw targeting Polish, Ukrainian, or Russian speakers. The malware employs innovative techniques like loading DLLs into legitimate processes, such as "explorer.exe," using the Windows registry for concealment. Core backdoors, DustyHammock (written in RUST) and ShadyHammock (C++), facilitate prolonged access, command execution, and data exfiltration, with DustyHammock focusing on reconnaissance and communication with command-and-control (C2) infrastructure. UAT-5647 also employs PuTTY's Plink to tunnel compromised networks, targeting edge devices for further infiltration.

UAT-5647’s recent campaigns underscore a sophisticated operational methodology, blending espionage and potential disruptive intent. Their evolving malware portfolio showcases a proficiency in RUST, GoLang, and C++, with frequent updates reflecting adaptability. The group’s targeting of Ukrainian government assets signals a focus on intelligence gathering, possibly to support broader strategic objectives. By infiltrating Polish and Ukrainian networks and compromising edge devices, UAT-5647 bolsters its stealth and evasion capabilities, posing ongoing threats to targeted nations.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
Execution T1059 Command and Scripting Interpreter
Persistence T1547 Boot or Logon Autostart Execution
Defense Evasion T1070 Indicator Removal
Credential Access T1003 OS Credential Dumping
Discovery T1016 System Network Configuration Discovery
Collection T1560 Archive Collected Data
Command and Control T1071 Application Layer Protocol
T1572 Protocol Tunneling
Exfiltration T1041 Exfiltration Over C2 Channel

REFERENCES:

The following reports contain further technical details:
https://blog.talosintelligence.com/uat-5647-romcom/

[/emaillocker]
crossmenu