
The attackers behind RomCom RAT are suspected of phishing attacks targeting the upcoming NATO summit in Vilnius and certain organizations supporting Ukraine abroad.
This finding comes from the BlackBerry Threat Research and Intelligence team that discovered two malicious documents sent from Hungarian IP addresses on July 4, 2023.
RomCom, which is also tracked under the names Tropical Scorpius, UNC2596, and Void Rabisu, recently emerged as a Ukrainian politician with close ties to Western countries and a US-based organization involved in helping refugees fleeing the war-torn country. It was observed that a cyberattack was being launched against a medical institution where it resides. .
The attack chain launched by this group was geopolitically motivated, using spear-phishing emails to lure victims to cloned websites hosting Trojanized versions of popular software. Targets include the military, food supply chains, and IT companies.
The latest decoy document that BlackBerry has identified is a fake letter (“Letter_NATO_Summit_Vilnius_2023_ENG(1) .docx”).
“The initial infection vector is still unknown, but the attackers likely relied on spear-phishing techniques to trick victims into clicking on a specially crafted replica of the Ukraine World Congress website,” said the Canadian company. said in a published analysis. last week.
Opening a file triggers an advanced execution sequence that retrieves an intermediate payload from a remote server, resulting in Follina, a currently patched security flaw affecting Microsoft’s Support Diagnostic Tool (MSDT). (CVE-2022-30190) is exploited to: Remote code execution.
🔐 PAM Security – Expert Solutions to Secure Sensitive Accounts
Gain the knowledge and strategies you need to transform your privileged access security strategy in this expert-led webinar.
reserve a spot
As a result, the RomCom RAT is deployed. This is an executable file written in C++ designed to gather and remotely extort information about a compromised system.
“Based on the nature of the upcoming NATO summit and the associated decoy documents sent by the threat actors, the targeted victims are Ukrainian representatives, foreign organizations and individuals supporting Ukraine,” Blackberry said. rice field.
“Based on the available information, we conclude that either this is a RomCom rebranding operation or that one or more members of the RomCom threat group are behind this new campaign in support of a new threat group. moderate to high confidence in