Inside SnipBot: The Latest RomCom Malware Variant
ID: bfff35f6-f3e4-5691-9125-6c7386431f44
STIX ID: report--bfff35f6-f3e4-5691-9125-6c7386431f44
Feed Name: Palo Alto Networks Unit 42
This report documents SnipBot, a newly observed RomCom 5.0 backdoor (Dec 2023–Jun 2024) that uses signed downloader executables, novel obfuscation and sandbox-evasion checks, COM-hijack persistence to inject DLLs into explorer.exe, and a feature-rich backdoor (file listing/upload/download, remote command execution, SOCKS/SSH proxying and targeted exfiltration). The authors reconstructed infection chains, post-infection activity via Cortex XDR telemetry, and provide extensive IoCs (SHA256 hashes, domains, IPs, registry keys) and detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
