EXECUTIVE SUMMARY
UAT-5647, a Russian-speaking threat actor group also known as RomCom, has been conducting a focused cyber campaign against high-profile Ukrainian government entities and select targets in Poland. Researchers have observed these threat actors deploying a revised version of their RomCom malware, named "SingleCamper," through complex infection chains. UAT-5647’s activity centers on espionage, aiming to gather sensitive data, with a potential for ransomware escalation. This latest variant utilizes a loopback address for stealthy communications, enhancing its evasive capacity. With ongoing geopolitical tensions, the group’s operations exhibit a dual-purpose strategy: data exfiltration for intelligence and, possibly, disruption through financial extortion.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
UAT-5647, a Russian-speaking threat actor group also known as RomCom, has been conducting a focused cyber campaign against high-profile Ukrainian government entities and select targets in Poland. Researchers have observed these threat actors deploying a revised version of their RomCom malware, named "SingleCamper," through complex infection chains. UAT-5647’s activity centers on espionage, aiming to gather sensitive data, with a potential for ransomware escalation. This latest variant utilizes a loopback address for stealthy communications, enhancing its evasive capacity. With ongoing geopolitical tensions, the group’s operations exhibit a dual-purpose strategy: data exfiltration for intelligence and, possibly, disruption through financial extortion.[emaillocker id="1283"]
The infection chain leverages spear-phishing techniques, leading to the deployment of sophisticated downloaders and backdoors. The initial payloads, RustClaw and MeltingClaw, enable persistence on infected systems, with RustClaw targeting Polish, Ukrainian, or Russian speakers. The malware employs innovative techniques like loading DLLs into legitimate processes, such as "explorer.exe," using the Windows registry for concealment. Core backdoors, DustyHammock (written in RUST) and ShadyHammock (C++), facilitate prolonged access, command execution, and data exfiltration, with DustyHammock focusing on reconnaissance and communication with command-and-control (C2) infrastructure. UAT-5647 also employs PuTTY's Plink to tunnel compromised networks, targeting edge devices for further infiltration.
UAT-5647’s recent campaigns underscore a sophisticated operational methodology, blending espionage and potential disruptive intent. Their evolving malware portfolio showcases a proficiency in RUST, GoLang, and C++, with frequent updates reflecting adaptability. The group’s targeting of Ukrainian government assets signals a focus on intelligence gathering, possibly to support broader strategic objectives. By infiltrating Polish and Ukrainian networks and compromising edge devices, UAT-5647 bolsters its stealth and evasion capabilities, posing ongoing threats to targeted nations.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1059 | Command and Scripting Interpreter |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1070 | Indicator Removal |
| Credential Access | T1003 | OS Credential Dumping |
| Discovery | T1016 | System Network Configuration Discovery |
| Collection | T1560 | Archive Collected Data |
| Command and Control | T1071 | Application Layer Protocol |
| T1572 | Protocol Tunneling | |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
REFERENCES:
The following reports contain further technical details:
https://blog.talosintelligence.com/uat-5647-romcom/