RomCom
Also reported as Storm-0978, Tropical Scorpius, Void Rabisu, TA829, Storm-0671 and 7 other names. Linked to Russia by four sources.
Reports per quarter
Techniques seen in the last two years
- T1071.001 5 reports
- T1566.002 4 reports
- T1113 3 reports
- T1189 3 reports
- T1190 3 reports
- T1546.015 3 reports
- T1555.003 3 reports
- T1560 3 reports
- T1566.001 3 reports
- T1005 2 reports
Show all 77 techniques Show fewer
- T1021 2 reports
- T1027.007 2 reports
- T1041 2 reports
- T1053.005 2 reports
- T1068 2 reports
- T1082 2 reports
- T1087 2 reports
- T1091 2 reports
- T1114.001 2 reports
- T1185 2 reports
- T1195 2 reports
- T1204.002 2 reports
- T1480 2 reports
- T1518 2 reports
- T1547.001 2 reports
- T1552.001 2 reports
- T1553.002 2 reports
- T1566.003 2 reports
- T1573.002 2 reports
- T1583 2 reports
- T1587.001 2 reports
- T1587.004 2 reports
- T1588.005 2 reports
- T1588.006 2 reports
- T1608 2 reports
- T1614 2 reports
- T1657 2 reports
- T1659 2 reports
- T1003 1 report
- T1003.001 1 report
- T1012 1 report
- T1016 1 report
- T1027.001 1 report
- T1027.002 1 report
- T1027.011 1 report
- T1027.013 1 report
- T1036 1 report
- T1036.001 1 report
- T1059.001 1 report
- T1059.007 1 report
- T1069 1 report
- T1072 1 report
- T1078 1 report
- T1083 1 report
- T1090 1 report
- T1112 1 report
- T1133 1 report
- T1135 1 report
- T1140 1 report
- T1204.004 1 report
- T1219 1 report
- T1482 1 report
- T1497 1 report
- T1557 1 report
- T1558.003 1 report
- T1559.001 1 report
- T1563.002 1 report
- T1565 1 report
- T1566 1 report
- T1571 1 report
- T1572 1 report
- T1574.001 1 report
- T1583.008 1 report
- T1584.001 1 report
- T1588.003 1 report
- T1592 1 report
- T1622 1 report
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2017-0144 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2017-3506 KEV
- CVE-2018-0171 KEV
- CVE-2018-6065 KEV
- CVE-2020-12641 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-35730 KEV
- CVE-2021-21551 KEV
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
Show all 38 CVEs Show fewer
- CVE-2021-27065 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-44026 KEV
- CVE-2022-24521 KEV ransomware
- CVE-2022-26500 KEV ransomware
- CVE-2022-26501 KEV ransomware
- CVE-2022-26504
- CVE-2022-26522
- CVE-2022-26523
- CVE-2022-27925 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2023-36884 KEV ransomware
- CVE-2024-11182 KEV
- CVE-2024-42009 KEV
- CVE-2024-49039 KEV ransomware
- CVE-2024-9680 KEV ransomware
- CVE-2025-29824 KEV ransomware
- CVE-2025-32433 KEV
- CVE-2025-49704 KEV ransomware
- CVE-2025-49706 KEV ransomware
- CVE-2025-53770 KEV ransomware
- CVE-2025-53771
- CVE-2025-6218 KEV
- CVE-2025-8088 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
Show all 54 reports Show fewer
-
The original link failed its last check. Original publisher Detailsfor DAMASCENED PEACOCK
-
Void Rabisu Targets Female Political Leaders with New Slimmed-Down ROMCOM Variant
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Void Rabisu Targets Female Political Leaders with New Slimmed-Down ROMCOM Variant
-
Void Rabisu’s Use of RomCom Backdoor Shows a Growing Shift in Threat Actors’ Goals
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Void Rabisu’s Use of RomCom Backdoor Shows a Growing Shift in Threat Actors’ Goals
-
Ukraine remains Russia’s biggest cyber focus in 2023
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ukraine remains Russia’s biggest cyber focus in 2023
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor RomCom Threat Actor Abuses KeePass and SolarWinds to Target Ukraine and Potentially the United Kingdom
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor RomCom Threat Actor Abuses KeePass and SolarWinds to Target Ukraine and Potentially the United Kingdom
-
Unattributed RomCom Threat Actor Spoofing Popular Apps Now Hits Ukrainian Militaries
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Unattributed RomCom Threat Actor Spoofing Popular Apps Now Hits Ukrainian Militaries
-
Novel News on Cuba Ransomware- Greetings From Tropical Scorpius
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Novel News on Cuba Ransomware- Greetings From Tropical Scorpius
-
CUBA Ransomware Campaign Analysis
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CUBA Ransomware Campaign Analysis
-
UNC2596 Observed Leveraging Vulnerabilities to Deploy Cuba Ransomware
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor UNC2596 Observed Leveraging Vulnerabilities to Deploy Cuba Ransomware
-
Le ransomware Cuba s’en prend aux serveurs Exchange
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Le ransomware Cuba s’en prend aux serveurs Exchange
-
Microsoft Exchange servers hacked to deploy Cuba ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Exchange servers hacked to deploy Cuba ransomware
-
(Ex)Change of Pace_ UNC2596 Observed Leveraging Vulnerabilities to Deploy Cuba Ransomware _ Mandiant
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor (Ex)Change of Pace_ UNC2596 Observed Leveraging Vulnerabilities to Deploy Cuba Ransomware _ Mandiant
-
(Ex)Change of Pace- UNC2596 Observed Leveraging Vulnerabilities to Deploy Cuba Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor (Ex)Change of Pace- UNC2596 Observed Leveraging Vulnerabilities to Deploy Cuba Ransomware
-
WeTheNorth- A New Canadian Dark Web Marketplace
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WeTheNorth- A New Canadian Dark Web Marketplace
Newest first. Details opens the report in Explore.