Russian Ukrainian hackers RomCom have been linked to new attacks targeting government agencies and Polish entities with the new RAT malware SingleCamper, at least since late 2023.

According to Cisco Talos, which tracks the group as UAT-5647, SingleCamper (also known as SnipBot or RomCom 5.0) is a new variant of the RomCom RAT.
" This version loads directly from the registry into memory and uses a loopback address to communicate with its loader ," security researchers Dmytro Korzhevin, Asheer Malhotra, Vanja Svajcer, and Vitor Ventura noted
See also: ScarCruft spreads RokRAT malware via Windows Zero-Day
The Russian hackers RomCom are known by various other names, including Storm-0978, Tropical Scorpius, UAC-0180, UNC2596, and Void Rabisu, and have been linked to various malicious activities, including ransomware, extortion, and targeted credential harvesting. They began their activities in 2022.
It is estimated that their attacks have increased in recent months, aiming to create persistence on compromised networks and steal data. These actions are consistent with espionage operations.
According to researchers, Russian hackers RomCom are expanding their tools and infrastructure to support a wide variety of malware components. These have been written in different languages, including C++ (ShadyHammock), Rust (DustyHammock), Go (GLUEEGG), and Lua (DROPCLUE).
The attacks typically begin with a spear-phishing email that delivers a downloader — either coded in C++ (MeltingClaw) or Rust (RustyClaw). These install the ShadyHammock and DustyHammock backdoors, respectively. At the same time, a decoy document is displayed to the recipient to prevent them from realizing the breach.
See also: PureCrypter loader used to distribute DarkVision RAT
DustyHammock communicates with a command and control (C2) server, executes commands and downloads files from the server, while ShadyHammock acts as a launchpad for the final malware payload, SingleCamper.
SingleCamper, the latest version of the RomCom RAT malware, can do a lot of things on compromised machines. It can download PuTTY's Plink tool to create remote tunnels with infrastructure controlled by the attackers, it can perform network reconnaissance, spread across the network, steal data, and more.
According to researchers, these attacks by Russian hackers RomCom, targeting important Ukrainian entities, likely serve two purposes: cyberespionage and financial gain. They create long-term access and steal data for as long as possible (cyberespionage) and deploy ransomware (disrupting targets and financial gain).

What are the best methods for protecting against RAT malware?
The first and most important method of protection is awareness and education. Users need to be aware of the techniques attackers use to spread malware so they can identify and avoid them.
See also: DCRat targets Russian-speaking users via HTML Smuggling
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Installing reliable security is another essential method of malware protection. This software should include antivirus, anti-spyware, and anti-malware features, as well as phishing protection.
It's also important to keep your operating system and all applications up to date. Updates include security that can protect your computer from the latest threats.
Finally, careful interaction with emails and file attachments is crucial. Never open attachments or click on links from unknown sources as they may contain malware.
Source: thehackernews.com
