Since at least late 2023, a new round of cyberattacks targeting Ukrainian government agencies and unidentified Polish companies have been connected to the Russian threat actor RomCom.
SingleCamper, also known as SnipBot or RomCom 5.0, is a variation of the RomCom RAT that is used in the incursions, according to Cisco Talos, which is keeping an eye on the activity cluster under the UAT-5647 alias.
Security researchers Dmytro Korzhevin, Asheer Malhotra, Vanja Svajcer, and Vitor Ventura observed that this version loads straight from the registry into memory and communicates with its loader via a loopback address.
RomCom has been involved in multi-motivational operations, including ransomware read more about Russian RomCom Attacks Target Ukrainian Government with New SingleCamper RAT Variant.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
