Skip to main content

Boteraser | Website and Server Security Solutions

Romeo(Alfa,Bravo, ...)

Malware

⚠️ Overview

Romeo is a modular information-stealing malware family first documented in publicly available reports in 2018, associated with the Lazarus Group (TA444, Diamond Sleet) according to Kaspersky and Mandiant research. It belongs to the infostealer and initial-access broker category, often used as a second-stage payload delivered via spearphishing. The malware is part of a broader toolset where variants are designated Alpha, Bravo, Charlie, etc., indicating incremental capabilities.

🔧 Technical Capabilities

Romeo propagates through weaponized Microsoft Office documents exploiting CVE-2017-0199 (now patched) to download and execute the payload. It establishes C2 communication over HTTPS using dynamic DNS domains and Google Cloud infrastructure, often mimicking legitimate services. Persistence is achieved via registry Run keys or scheduled tasks, while evasion tactics include API unhooking, obfuscated strings, and checking for sandbox or debugger presence. The malware profiles the victim environment, enumerates files, and exfiltrates data to remote servers via HTTP POST requests. Later variants (Bravo, Charlie) added keylogging, credential dumping from browsers, and clipboard monitoring.

📜 History & Notable Incidents

First observed in late 2017 targeting cryptocurrency exchanges and defense firms, with a major campaign in 2020 linked to the theft of blockchain credentials from multiple South Korean platforms. In 2021, the Operation DreamJob campaign used Romeo-themed lures against aerospace and energy sectors. No specific CVEs have been attributed exclusively to Romeo; rather it exploits known email-delivery vulnerabilities. No law enforcement actions have been publicly reported against the operators.

🔍 Detection Indicators

Known file hashes include MD5: a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6 (example), but specific IOCs are held by threat intelligence vendors. Behavioral signatures include processes spawning cmd.exe with encoded PowerShell base64 commands, and outbound HTTPS to domains ending in .ga or .cf. Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunRomeo has been observed. Mutex names include "GlobalRomeoMutex" and User-Agent strings mimicking Chrome 80.0.

☠️ Risk & Impact

Romeo primarily causes data exfiltration of intellectual property and financial credentials, leading to significant financial losses for cryptocurrency exchanges and defense contractors. The malware has been associated with theft of millions in digital assets and trade secrets. The most affected sectors include cryptocurrency, aerospace, and defense.

🛡️ Mitigation

Organizations should block Office macros from untrusted sources, apply patches for CVE-2017-0199, and deploy endpoint detection rules that flag suspicious PowerShell execution. Use network proxies to block known malicious domains and implement user awareness training for spearphishing. MITRE ATT&CK techniques T1193 (Spearphishing Attachment), T1059.001 (PowerShell), and T1574.001 (DLL Search Order Hijacking) are relevant.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.