Russian RomCom Utilizing SocGholish to Deliver Mythic Agent to U.S. Companies Supporting Ukraine
ID: a03e2a74-3d78-5349-a1ee-e51f579d0836
STIX ID: report--a03e2a74-3d78-5349-a1ee-e51f579d0836
Feed Name: Arctic Wolf
Date Published: 2025-11-25
Date Updated: 2026-07-26
Author: Jacob Faires and the Arctic Wolf Labs team
Arctic Wolf Labs observed a September 2025 incident in which SocGholish malvertising (attributed to TA569) delivered a RomCom Mythic loader (msedge.dll) to a U.S. engineering firm with ties to Ukraine; Arctic Wolf's Aurora endpoint defenses detected and quarantined the loader, preventing compromise. The report provides a technical breakdown of the SocGholish infection chain, the Mythic dynamichttp agent, associated C2 domains and IOCs, MITRE ATT&CK mappings, and assesses with medium-to-high confidence that GRU Unit 29155 is leveraging SocGholish for targeted intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
