logo

Russian RomCom Utilizing SocGholish to Deliver Mythic Agent to U.S. Companies Supporting Ukraine

ID: a03e2a74-3d78-5349-a1ee-e51f579d0836

STIX ID: report--a03e2a74-3d78-5349-a1ee-e51f579d0836

Feed Name: Arctic Wolf

Threat Score
85/100

Date Published: 2025-11-25

Date Updated: 2026-07-26

Author: Jacob Faires and the Arctic Wolf Labs team

...
...

Arctic Wolf Labs observed a September 2025 incident in which SocGholish malvertising (attributed to TA569) delivered a RomCom Mythic loader (msedge.dll) to a U.S. engineering firm with ties to Ukraine; Arctic Wolf's Aurora endpoint defenses detected and quarantined the loader, preventing compromise. The report provides a technical breakdown of the SocGholish infection chain, the Mythic dynamichttp agent, associated C2 domains and IOCs, MITRE ATT&CK mappings, and assesses with medium-to-high confidence that GRU Unit 29155 is leveraging SocGholish for targeted intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.