Uptime Hamster: 10d 7h 13mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza RomCom

RomCom

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Aliases: Storm-0978, UAT-5647, storm-1359, CVE-2023-36884, dustyhammock, meltingclaw, romcom, rustyclaw, shadyhammock, singlecamper, snipbot, uat-5647
Ver en IntelTracker → APTTrail →
RomCom, also known by aliases such as Storm-0978, UAT-5647, and Void Rabisu, is an advanced persistent threat group that emerged around 2022. Assessed with high confidence to be of Russian origin, the group's primary motivation is a dual track of cyber espionage aligned with Russian geopolitical interests and financially motivated attacks. Initially observed using trojanized installers against Ukrainian government and military officials, RomCom has demonstrated a continuous evolution in its operational model, integrating ransomware and double extortion tactics. A distinguishing characteristic of RomCom is its rapid adoption and exploitation of zero-day vulnerabilities and its ability to constantly refine its custom malware, evolving through multiple distinct versions like SnipBot (RomCom 5.0), making it a highly adaptable and unpredictable threat.

Aliases del actor

Storm-0978UAT-5647storm-1359CVE-2023-36884dustyhammockmeltingclawromcomrustyclawshadyhammocksinglecampersnipbotuat-5647

Actores similares

cve-2023-36884actor · 1stormousransomware · 177apt-equationgroupactor · 1cve-2023-41991actor · 1uat-5918actor · 1crimson-sandstormactor · 1Equationactor · 1Aquatic Pandaactor · 1Storm-1811actor · 1Storm-0501apt · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteupduckduckgo.comRomCom
DLS / leak siteupduckduckgo.comRomCom
Motivacion