logo

UAT-5647 targets Ukrainian and Polish entities with RomCom malware variants

ID: ed8d84c1-f3d9-5e59-b721-b65c9eb12d25

STIX ID: report--ed8d84c1-f3d9-5e59-b721-b65c9eb12d25

Feed Name: Cisco Talos

Threat Score
90/100

Date Published: 2024-10-17

Date Updated: 2026-04-27

Author: Dmytro Korzhevin

...
...

Cisco Talos describes an active, Russian-speaking APT campaign tracked as UAT-5647 (RomCom) that has been active since late 2023 and targets Ukrainian government and possibly Polish entities. The report details a multi-stage infection chain delivered via spear-phishing, two downloader families (RustyClaw, MeltingClaw) that establish persistence and deploy two backdoors (Rust-based DustyHammock and C++ ShadyHammock), and a registry-loaded RomCom variant (SingleCamper). Operators performed extensive network reconnaissance, tunneling using PuTTY Plink to expose internal edge-device interfaces, staged file collection and exfiltration, and used multi-language tooling; the report includes hashes, domains, IPs and mitigation/detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.