HomeSecurityRomCom hackers target Ukrainian services with SingleCamper RAT

RomCom hackers target Ukrainian services with SingleCamper RAT

Russian Ukrainian hackers RomCom have been linked to new attacks targeting government agencies and Polish entities with the new RAT malware SingleCamper, at least since late 2023.

Russian hackers RomCom

According to Cisco Talos, which tracks the group as UAT-5647, SingleCamper (also known as SnipBot or RomCom 5.0) is a new variant of the RomCom RAT.

" This version loads directly from the registry into memory and uses a loopback address to communicate with its loader ," security researchers Dmytro Korzhevin, Asheer Malhotra, Vanja Svajcer, and Vitor Ventura noted

See also: ScarCruft spreads RokRAT malware via Windows Zero-Day

The Russian hackers RomCom are known by various other names, including Storm-0978, Tropical Scorpius, UAC-0180, UNC2596, and Void Rabisu, and have been linked to various malicious activities, including ransomware, extortion, and targeted credential harvesting. They began their activities in 2022.

It is estimated that their attacks have increased in recent months, aiming to create persistence on compromised networks and steal data. These actions are consistent with espionage operations.

According to researchers, Russian hackers RomCom are expanding their tools and infrastructure to support a wide variety of malware components. These have been written in different languages, including C++ (ShadyHammock), Rust (DustyHammock), Go (GLUEEGG), and Lua (DROPCLUE).

The attacks typically begin with a spear-phishing email that delivers a downloader — either coded in C++ (MeltingClaw) or Rust (RustyClaw). These install the ShadyHammock and DustyHammock backdoors, respectively. At the same time, a decoy document is displayed to the recipient to prevent them from realizing the breach.

See also: PureCrypter loader used to distribute DarkVision RAT

DustyHammock communicates with a command and control (C2) server, executes commands and downloads files from the server, while ShadyHammock acts as a launchpad for the final malware payload, SingleCamper.

SingleCamper, the latest version of the RomCom RAT malware, can do a lot of things on compromised machines. It can download PuTTY's Plink tool to create remote tunnels with infrastructure controlled by the attackers, it can perform network reconnaissance, spread across the network, steal data, and more.

According to researchers, these attacks by Russian hackers RomCom, targeting important Ukrainian entities, likely serve two purposes: cyberespionage and financial gain. They create long-term access and steal data for as long as possible (cyberespionage) and deploy ransomware (disrupting targets and financial gain).

SingleCamper RAT malware

What are the best methods for protecting against RAT malware?

The first and most important method of protection is awareness and education. Users need to be aware of the techniques attackers use to spread malware so they can identify and avoid them.

See also: DCRat targets Russian-speaking users via HTML Smuggling

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Installing reliable security is another essential method of malware protection. This software should include antivirus, anti-spyware, and anti-malware features, as well as phishing protection.

It's also important to keep your operating system and all applications up to date. Updates include security that can protect your computer from the latest threats.

Finally, careful interaction with emails and file attachments is crucial. Never open attachments or click on links from unknown sources as they may contain malware.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS