logo

RomCom Malware Resurfaces With SnipBot Variant

ID: 48412244-1532-51f8-9a4c-72e808fce626

STIX ID: report--48412244-1532-51f8-9a4c-72e808fce626

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-09-24

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

SnipBot (RomCom v5) is a new variant of the RomCom RAT observed since December; it spreads via phishing PDFs or executables, uses valid code-signing certificates for the downloader, employs control-flow obfuscation and anti-sandbox checks, and supports command execution, module download, and exfiltration to attacker-controlled servers. Unit 42 links the actor to prior RomCom activity (including attacks on Ukraine and its supporters) and notes the group's shift from financially motivated operations toward exclusive intelligence-gathering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.