logo

New RomCom malware variant 'SnipBot' spotted in data theft attacks

ID: 25e883e0-68d2-52a7-9ccc-04f338f452da

STIX ID: report--25e883e0-68d2-52a7-9ccc-04f338f452da

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-09-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Unit 42 researchers identified SnipBot (RomCom 5.0), a sophisticated backdoor used in phishing-driven campaigns to steal data and pivot across networks. SnipBot extends RomCom with 27 commands for granular data collection and archiving, persists via COM hijacking and signed downloaders, uses in-memory encrypted DLLs and anti-sandbox checks, and performs AD discovery and targeted exfiltration (archiving with WinRAR/7-Zip and exfil via PuTTY SCP); observed targets include IT services, legal, and agriculture sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.