logo

RomCom__2022__RomCom_Threat_Actor_Abuses_KeePass_and_SolarWinds_to_Target_Ukraine_and_Potentially_the_United_Kingdom.pdf

ID: b1776d25-a1fc-4be1-896b-1a1da1767fbb

STIX ID: report--b1776d25-a1fc-4be1-896b-1a1da1767fbb

Threat Score

78/100

Uploaded: 2026-08-19

Published Date: 2022-12-07

Last Modified Date: 2022-12-07

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
BlackBerry researchers describe active RomCom RAT campaigns that spoof SolarWinds, KeePass and PDF Reader Pro to distribute Trojanized installers and droppers targeting Ukrainian entities and potentially UK-based victims; the report contains technical TTPs, extracted sample details, C2 certificate information, and numerous IoCs (file names and hashes) to support detection and response.