Tag: TA829

TA829 and UNK_GreenSec Share Tactics and Infrastructure in Ongoing Malware Campaigns
News

TA829 and UNK_GreenSec Share Tactics and Infrastructure in Ongoing Malware Campaigns

Researchers studying cybersecurity have identified tactical parallels between the threat actors responsible for the RomCom RAT and a cluster that has been seen deploying a loader known as TransferLoader. Under the alias TA829, the RomCom RAT perpetrators and a group called UNK_GreenSec are being monitored by enterprise security firm Proofpoint for their involvement with TransferLoader. CIGAR, Nebulous Mantis, Storm-0978, Tropical Scorpius, UAC-0180, UAT-5647, UNC2596, and Void Rabisu are some other names for the latter. As part of their study of TA829, the business claimed to have found UNK_GreenSec, characterizing it as employing an unusually high degree of comparable email lure themes, distribution strategies, landing pages, and infrastructure. Given its capacity to carry out b...