By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Russian RomCom Attacks Target Ukrainian Government with New SingleCamper RAT Variant
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Russian RomCom Attacks Target Ukrainian Government with New SingleCamper RAT Variant
Tech News

Russian RomCom Attacks Target Ukrainian Government with New SingleCamper RAT Variant

By Viral Trending Content 3 Min Read
Share
SHARE

Oct 17, 2024Ravie LakshmananThreat Intelligence / Malware

SingleCamper RAT Variant

The Russian threat actor known as RomCom has been linked to a new wave of cyber attacks aimed at Ukrainian government agencies and unknown Polish entities since at least late 2023.

The intrusions are characterized by the use of a variant of the RomCom RAT dubbed SingleCamper (aka SnipBot or RomCom 5.0), said Cisco Talos, which is monitoring the activity cluster under the moniker UAT-5647.

“This version is loaded directly from the registry into memory and uses a loopback address to communicate with its loader,” security researchers Dmytro Korzhevin, Asheer Malhotra, Vanja Svajcer, and Vitor Ventura noted.

Cybersecurity

RomCom, also tracked as Storm-0978, Tropical Scorpius, UAC-0180, UNC2596, and Void Rabisu, has engaged in multi-motivational operations such as ransomware, extortion, and targeted credential gathering since its emergence in 2022.

It’s been assessed that the operational tempo of their attacks has increased in recent months with an aim to set up long-term persistence on compromised networks and exfiltrate data, suggesting a clear espionage agenda.

To that end, the threat actor is said to be “aggressively expanding their tooling and infrastructure to support a wide variety of malware components authored in diverse languages and platforms” such as C++ (ShadyHammock), Rust (DustyHammock), Go (GLUEEGG), and Lua (DROPCLUE).

The attack chains start with a spear-phishing message that delivers a downloader — either coded in C++ (MeltingClaw) or Rust (RustyClaw) — which serves to deploy the ShadyHammock and DustyHammock backdoors, respectively. In parallel, a decoy document is displayed to the recipient to maintain the ruse.

While DustyHammock is engineered to contact a command-and-control (C2) server, run arbitrary commands, and download files from the server, ShadyHammock acts as a launchpad for SingleCamper as well as listening for incoming commands.

Despite’s ShadyHammock additional features, it’s believed that it’s a predecessor to DustyHammock, given the fact that the latter was observed in attacks as recently as September 2024.

Cybersecurity

SingleCamper, the latest version of RomCom RAT, is responsible for a wide range of post-compromise activities, which entail downloading the PuTTY’s Plink tool to establish remote tunnels with adversary-controlled infrastructure, network reconnaissance, lateral movement, user and system discovery, and data exfiltration.

“This specific series of attacks, targeting high profile Ukrainian entities, is likely meant to serve UAT-5647’s two-pronged strategy in a staged manner – establish long-term access and exfiltrate data for as long as possible to support espionage motives, and then potentially pivot to ransomware deployment to disrupt and likely financially gain from the compromise,” the researchers said.

“It is also likely that Polish entities were also targeted, based on the keyboard language checks performed by the malware.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Hybrid work crucial for more than 50pc of employees, finds IrishJobs

Who Approved This Agent? Rethinking Access, Accountability, and Risk in the Age of AI Agents

ICE Asks Companies About ‘Ad Tech and Big Data’ Tools It Could Use in Investigations

Asus ROG Phone & Zenfone Smartphones No Longer Being Made

Siri’s Transformation in iOS 27: Apple’s AI Chatbot Explained

TAGGED: Advanced Persistent Threat, Cyber Attack, cyber espionage, Cyber Security, Cybersecurity, Internet, Malware, phishing attack, Ransomware, Threat Intelligence
Share This Article
Facebook Twitter Copy Link
Previous Article Surge In Bitcoin Activity: Whales Transactions Hit New Highs, Is A Bull Run Brewing?
Next Article Euroclear makes first Asia investment with Marketnode stake
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

No. 19 Kansas Finishes on 27-7 Run To Beat Kansas State, 86-62
Sports
The best winter music in video games
Gaming News
In the case of the Federal Reserve, Supreme Court appears to carve out a murky exception
Business
Today in History: January 25, Charles Manson convicted of murder, conspiracy
World News
Calls grow for ICE to leave Minnesota after latest shooting of citizen
World News
Colombia’s second-largest pension fund to offer Bitcoin exposure
Crypto
The Super Mario Galaxy Movie Direct Set for January 25th
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

No. 19 Kansas Finishes on 27-7 Run To Beat Kansas State, 86-62

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
No. 19 Kansas Finishes on 27-7 Run To Beat Kansas State, 86-62
January 25, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?