RomCom / Storm-0978 (Russia)
Russian cybercrime/espionage hybrid (formal state relationship assessed, not publicly confirmed) · Dual mandate: financial (Underground ransomware) and state-directed intelligence collection (espionage against NATO and Ukraine)
Tactics, Techniques & Procedures (TTPs)
- Firefox zero-day exploitation (CVE-2024-9680, no user interaction required) combined with Windows privilege escalation zero-day — one of few criminal groups with confirmed zero-day development
- SnipBot modular backdoor (2024): file theft, command execution, process management with minimal footprint
- PEAPOD RAT (2023): lightweight persistent access for targeted espionage against specific high-value individuals
- Underground ransomware operations — criminal extortion alongside intelligence tasking from same infrastructure
- Trojanised software mimicking legitimate tools (Advanced IP Scanner, PDF readers, KeePass) for initial access
- Precision social engineering against specific NATO event attendees and political targets
- Exploitation of Windows zero-days for privilege escalation in espionage chain
Known Targets
Analyst Notes
RomCom simultaneously conducts state-directed espionage against NATO and Ukrainian targets while running Underground ransomware operations for financial gain — a rare criminal/intelligence hybrid. The Firefox+Windows zero-day chain (2024) placed RomCom among a small group of criminal actors with confirmed zero-day development capability. Both tracks (SnipBot espionage and Underground ransomware) operate from the same infrastructure with different objectives, suggesting either state tasking alongside freelance criminal activity or a state contractor model. Ukraine and NATO targeting clearly serves Russian intelligence priorities.
Also Known As