SHADOW-VOID-042
0 incidentes
0 paises
0 sectores
apt RU Ultimo: -
SHADOW-VOID-042 emerged in October 2025 as a temporary intrusion set, identified through spear-phishing campaigns that demonstrated significant technical overlap with Void Rabisu, a threat actor aligned with Russian interests. While Void Rabisu evolved from financially motivated cybercrime, originally linked to the Cuba ransomware, into a primary espionage threat actor, SHADOW-VOID-042's observed activities are focused on intelligence collection rather than direct ransomware deployment. This group specifically distinguishes itself by its highly targeted approach, employing tailored spear-phishing lures such as fake software updates and HR-related documents, and notably compromised cybersecurity vendors, including a Trend Micro subsidiary, by impersonating their legitimate updates. The group is currently tracked separately from Void Rabisu due to the absence of a definitive link to the ROMCOM backdoor in observed SHADOW-VOID-042 campaigns and a lack of confirmed Ukraine-specific targeti
Sectores objetivo (SOCRadar)
Computer Systems Design and Related Services