New RomCom malware variant 'SnipBot' spotted in data theft attacks
ID: 25e883e0-68d2-52a7-9ccc-04f338f452da
STIX ID: report--25e883e0-68d2-52a7-9ccc-04f338f452da
Feed Name: Bleeping Computer
Unit 42 researchers identified SnipBot (RomCom 5.0), a sophisticated backdoor used in phishing-driven campaigns to steal data and pivot across networks. SnipBot extends RomCom with 27 commands for granular data collection and archiving, persists via COM hijacking and signed downloaders, uses in-memory encrypted DLLs and anti-sandbox checks, and performs AD discovery and targeted exfiltration (archiving with WinRAR/7-Zip and exfil via PuTTY SCP); observed targets include IT services, legal, and agriculture sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
