TA829 and UNK_GreenSec Share Tactics and Infrastructure in Ongoing Malware Campaigns
Researchers studying cybersecurity have identified tactical parallels between the threat actors responsible for the RomCom RAT and a cluster that has been seen deploying a loader known as TransferLoader.
Under the alias TA829, the RomCom RAT perpetrators and a group called UNK_GreenSec are being monitored by enterprise security firm Proofpoint for their involvement with TransferLoader. CIGAR, Nebulous Mantis, Storm-0978, Tropical Scorpius, UAC-0180, UAT-5647, UNC2596, and Void Rabisu are some other names for the latter.
As part of their study of TA829, the business claimed to have found UNK_GreenSec, characterizing it as employing an unusually high degree of comparable email lure themes, distribution strategies, landing pages, and infrastructure.
Given its capacity to carry out b...

