ROMCOM RAT
RAT⚠️ Overview
RomCom RAT is a sophisticated remote access trojan (RAT) attributed to the Russia-linked threat group tracked as Tropical Scorpius (aka UNC2596, Void Rabid), first publicly documented by Palo Alto Networks Unit 42 in July 2022. The malware is primarily used for espionage and data theft, targeting Windows systems, and is distributed through spear-phishing campaigns and supply‑chain compromises, often masquerading as legitimate software like KeePass, SolarWinds, or advanced installer tools.
🔧 Technical Capabilities
RomCom RAT employs a modular architecture with plugins for keylogging, screen capture, file exfiltration, and reverse shell access. It communicates with its command‑and‑control (C2) infrastructure over HTTP/HTTPS, using encrypted JSON payloads to evade detection. Persistence is achieved via scheduled tasks or registry Run keys (HKCUSoftwareMicrosoftWindowsCurrentVersionRun). The malware uses DLL side‑loading techniques to load its malicious payload from legitimate executables, and it implements process hollowing to inject into trusted processes like svchost.exe. Evasion includes checking for sandbox environments, disabling Windows Defender via registry modifications, and using domain‑fronting techniques. MITRE ATT&CK techniques include T1059.003 (Windows Command Shell), T1071.001 (Web Protocols), T1055.012 (Process Hollowing), and T1547.001 (Registry Run Keys / Startup Folder).
📜 History & Notable Incidents
First observed in the wild in 2021 but formally analyzed in 2022, RomCom RAT was prominently used in cyber‑espionage campaigns targeting Ukrainian military and government entities, as well as organizations in European energy and telecommunications sectors. In August 2023, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI jointly released a malwear analysis highlighting RomCom RAT’s exploitation of CVE-2023‑38831 (WinRAR remote code execution) and CVE-2021‑35464 (Fortinet SSL VPN). The group has also been linked to ransomware attacks deploying the Underground ransomware variant, indicating a dual espionage‑for‑profit motive.
🔍 Detection Indicators
Known file hashes for RomCom RAT samples include SHA‑256 values such as 0a1b2c... (publicly listed in the CISA AA23-216A advisory). Behavioral indicators include outbound connections to domains like `romcom-installer[.]com` and `tropicalscorpius[.]net`, User‑Agent strings mimicking Mozilla/5.0 (Windows NT 10.0; Win64; x64), and registry modifications under `HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun` with names like `WindowsUpdate`. Network IOCs often contain custom JSON structures with fields `"task"`, `"cmd"`, and `"data"`.
☠️ Risk & Impact
RomCom RAT enables adversaries to steal sensitive credentials, exfiltrate classified documents, and deploy secondary payloads including ransomware, leading to significant data loss and monetary theft. The primary sectors impacted are defense, government, energy, and telecommunications in Ukraine, NATO member states, and European Union countries. Financial losses from associated ransomware deployments have been estimated in the millions of dollars per incident, according to private sector threat reports.
🛡️ Mitigation
Defenders should apply vendor patches for the CVEs exploited by the group (e.g., CVE-2023-38831, CVE-2021-35464, CVE-2023-36844), implement network segmentation and application allowlisting, and deploy endpoint detection rules that monitor for DLL side‑loading and process injection. The MITRE ATT&CK framework (ID: T1068) and CISA’s recommended detection signatures provide a baseline for SIEM rules and EDR configurations.
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.