UAT-5647 targets Ukrainian and Polish entities with RomCom malware variants
ID: ed8d84c1-f3d9-5e59-b721-b65c9eb12d25
STIX ID: report--ed8d84c1-f3d9-5e59-b721-b65c9eb12d25
Feed Name: Cisco Talos
Cisco Talos describes an active, Russian-speaking APT campaign tracked as UAT-5647 (RomCom) that has been active since late 2023 and targets Ukrainian government and possibly Polish entities. The report details a multi-stage infection chain delivered via spear-phishing, two downloader families (RustyClaw, MeltingClaw) that establish persistence and deploy two backdoors (Rust-based DustyHammock and C++ ShadyHammock), and a registry-loaded RomCom variant (SingleCamper). Operators performed extensive network reconnaissance, tunneling using PuTTY Plink to expose internal edge-device interfaces, staged file collection and exfiltration, and used multi-language tooling; the report includes hashes, domains, IPs and mitigation/detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
