RomCom__2022__RomCom_Threat_Actor_Abuses_KeePass_and_SolarWinds_to_Target_Ukraine_and_Potentially_the_United_Kingdom.pdf
ID: b1776d25-a1fc-4be1-896b-1a1da1767fbb
STIX ID: report--b1776d25-a1fc-4be1-896b-1a1da1767fbb
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2022-12-07
Last Modified Date: 2022-12-07
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
BlackBerry researchers describe active RomCom RAT campaigns that spoof SolarWinds, KeePass and PDF Reader Pro to distribute Trojanized installers and droppers targeting Ukrainian entities and potentially UK-based victims; the report contains technical TTPs, extracted sample details, C2 certificate information, and numerous IoCs (file names and hashes) to support detection and response.
