Skip to content
Deep Dive high GovernmentdefensetechnologyHealthcarefinancial-services

RomCom / Storm-0978: Russia's Hybrid Espionage-Criminal Threat Actor

Executive Summary

RomCom is a Russian-origin threat actor that simultaneously pursues financially motivated ransomware and data extortion operations and targeted espionage campaigns against NATO member state governments, Ukrainian government entities, and defence organisations. The dual mandate — criminal revenue alongside state intelligence collection — is what makes RomCom distinctive and difficult to counter: the same infrastructure and tooling serve two different objectives, and the affiliates or operators who run ransomware deployments for revenue may be tasked with espionage implant deployment for separate handlers.

The group made global headlines in October 2023 when ESET researchers reported that RomCom had exploited a chained zero-day attack — combining a Firefox memory corruption vulnerability (CVE-2023-4853, the WebP zero-day) with a Windows SmartScreen bypass (CVE-2023-36025) — to achieve no-click code execution in a browser phishing attack against European government and defence targets. The sophistication of that campaign placed RomCom firmly in the tier of state-sponsored threat actors capable of developing and deploying zero-day exploits, despite the group’s simultaneous operation of commercially oriented ransomware.

Through 2024 and 2025, RomCom maintained continuous activity against Ukrainian government and military targets, expanded espionage targeting to include pharmaceutical companies and energy organisations in EU member states, and evolved its malware families from the original RomCom backdoor to SnipBot and PEAPOD variants with enhanced modularity and evasion.


Threat Actor Profile

Primary aliases: RomCom (ESET), Storm-0978 (Microsoft), Tropical Scorpius (Palo Alto Unit 42), UNC2596 (Mandiant), Void Rabisu (Trend Micro)

Origin: Russia; suspected GRU or FSB affiliation, though public attribution to a specific Russian intelligence service remains contested. The group’s targeting overlaps substantially with Russian strategic interests.

Active since: 2020, with public documentation from 2022 onwards

Primary mandate: Dual — financially motivated ransomware/extortion (Cuba ransomware, Underground ransomware) and targeted intelligence collection against Ukrainian government, NATO member state governments, and defence organisations

Ransomware families operated: Cuba ransomware (2021–2023), Underground ransomware (2023–present)

Backdoors/implants: RomCom backdoor (2022), RomCom 3.0/4.0 variants, PEAPOD (2023), SnipBot (2024–present)

The hybrid model — criminal revenue alongside intelligence tasking — is not unique to RomCom. North Korea’s Lazarus Group has operated similarly for over a decade. What makes RomCom’s configuration notable is the targeting profile: while Lazarus targets financial institutions and cryptocurrency exchanges for revenue, RomCom targets primarily government and defence organisations for both espionage and ransomware deployment. This means the same types of victim organisations face both encryption attacks for ransom and silent implant-based exfiltration.

The precise relationship between the espionage and criminal components is not publicly established. CISA’s 2023 advisory noted that some Storm-0978 ransomware campaigns against defence contractors overlapped temporally with intelligence-focused phishing using the same infrastructure. The most plausible interpretation is that criminal ransomware revenue subsidises operations, while intelligence-focused intrusions are either directed by state handlers or opportunistically tasked when the access is interesting.


TTPs and Tradecraft

Initial Access: Zero-Day Exploitation and Spearphishing

RomCom’s highest-profile initial access technique is zero-day exploitation delivered via browser-based attacks. In October 2023, ESET documented a campaign combining two unpatched vulnerabilities:

  • CVE-2023-4853 (later reclassified; the WebP/libwebp heap buffer overflow affecting Mozilla Firefox and Chrome) allowed arbitrary code execution in the browser sandbox
  • CVE-2023-36025 (Windows SmartScreen bypass) allowed escape from the browser sandbox to execute code on the underlying system

The combination created a drive-by compromise requiring no user interaction beyond visiting a malicious webpage. RomCom served the exploit from domains mimicking legitimate organisations, primarily EU government and defence sector entities. This level of zero-day capability — developing or purchasing working exploits for both the browser and the OS simultaneously — is characteristic of well-resourced state-sponsored actors.

For less sensitive targets and financial campaigns, the group uses spearphishing with document lures, including:

  • Fake invitations to NATO events and conferences (the July 2023 NATO summit in Vilnius generated a wave of targeted lures)
  • Documents mimicking Ukrainian government ministry communications
  • Fake pharmaceutical and healthcare sector credentials
  • Trojanised versions of legitimate software (including a documented case of a trojanised version of Advanced IP Scanner)

Malware: RomCom Backdoor Family Evolution

The RomCom backdoor has undergone substantial development since its initial documentation in 2022. The evolution reflects both operational requirements and the group’s response to defensive detection:

RomCom 1.0–2.0 (2022–2023): A C++ remote access tool with standard backdoor functionality — file operations, shell command execution, screen capture, keylogging. Notable for its use of Windows COM objects and obfuscated command-and-control communications designed to blend with legitimate Windows traffic.

PEAPOD (2023): An updated RomCom variant with enhanced anti-analysis features, better C2 resilience, and additional modules for credential harvesting from browsers and mail clients. Used in campaigns targeting EU government officials and Ukrainian military contacts.

SnipBot (2024–present): The most recent publicly documented variant, first reported by ESET in 2024. SnipBot is a more modular implant with plugin-based architecture — the core loader retrieves additional modules from C2 infrastructure rather than carrying full functionality in the initial payload. This reduces the static footprint and allows the C2 operator to customize capability delivery per victim. SnipBot has been observed with plugins for document collection, email archive exfiltration, browser credential theft, and network enumeration.

C2 Infrastructure

RomCom’s command-and-control infrastructure consistently uses a few patterns:

  • HTTPS to domains that mimic legitimate services (cloud providers, software vendors, government entities)
  • Hosting on bulletproof providers or compromised legitimate servers
  • Fast-flux DNS to complicate infrastructure takedowns
  • Use of legitimate cloud services (GitHub, Google Drive) in some variants for staged payload delivery

The group rotates infrastructure frequently and has demonstrated the ability to stand up new C2 within 24–48 hours of domain takedowns.

Lateral Movement and Persistence

Post-compromise activity varies by objective. In ransomware campaigns, the group follows a standard criminal TTP:

  • Credential harvesting with tools including Mimikatz, LaZagne
  • Active Directory enumeration (BloodHound)
  • Deployment of rclone or Mega for bulk exfiltration prior to encryption
  • Cuba/Underground ransomware deployment via domain controller or GPO

In espionage campaigns, the focus shifts to quiet persistence and targeted data collection:

  • SnipBot or PEAPOD implant deployed on high-value machines
  • Selective document collection from specific users
  • Longer dwell times (months rather than days)
  • Avoidance of broad lateral movement to minimise detection surface

Targeting and Victim Sectors

RomCom’s targeting reflects the dual mandate. The ransomware component concentrates on sectors where downtime and data sensitivity create leverage:

  • US and Latin American healthcare organisations (Cuba ransomware period, 2021–2023)
  • Financial services and financial infrastructure
  • Manufacturing and critical infrastructure

The espionage component concentrates on:

  • Ukrainian government and military: The group has targeted Ukrainian ministries, military command and control infrastructure, and defence-related organisations continuously since 2022. Targeting intensified following the invasion and has maintained high operational tempo through 2025.
  • NATO member state governments: EU member state governments with policy relevance to Ukraine — particularly Poland, Czech Republic, Germany, Slovakia, and the Baltic states — have been targeted with spearphishing. The NATO summit in Vilnius (July 2023) was used as phishing lure theme for attacks against summit attendees.
  • Defence contractors and defence industrial base: Both EU and US defence contractors have been targeted, consistent with intelligence collection objectives around weapons systems, logistics, and defence policy.
  • Pharmaceutical and healthcare: A notable expansion in 2024–2025 targeted pharmaceutical companies with R&D in areas of interest to Russian state priorities (biologics, vaccines). This targeting is unusual for a criminal/espionage hybrid and suggests tasking that goes beyond opportunistic revenue.

Historical Incidents and Impact

2021–2023: Cuba Ransomware Operations RomCom operated Cuba ransomware, which CISA attributed to the group in 2022 and 2023. Cuba was responsible for attacks on over 100 organisations globally, including US critical infrastructure entities, extracting over $60 million in ransom payments. The group combined ransomware with data theft and published stolen data on a dedicated leak site when ransoms were refused.

July 2023: NATO Summit Phishing Campaign Microsoft and CISA documented a targeted campaign using the NATO summit in Vilnius as a lure. Documents designed to mimic Ukrainian World Congress communications were used to deliver the RomCom backdoor to government officials, defence ministry contacts, and think-tank analysts across NATO member states. The campaign demonstrated the group’s awareness of geopolitical events as targeting opportunities.

October 2023: Firefox/Windows Zero-Day Chain ESET documented exploitation of CVE-2023-4853 and CVE-2023-36025 in attacks against European targets. This remains the most technically sophisticated known RomCom operation — a two-zero-day chain delivering compromise without user interaction. The vulnerability was patched by Mozilla within 24 hours of responsible disclosure; the Windows component was patched in November 2023. Victims included European government officials and defence sector employees.

2024–2025: SnipBot and Pharmaceutical Targeting ESET’s 2024 SnipBot report documented new intrusions at pharmaceutical companies and professional service providers in Europe and North America. The SnipBot modular architecture represented a maturation of operational security — harder to detect at scale, more selective in payload delivery. Victims included at least two European pharmaceutical firms involved in vaccine research.

2025–2026: Underground Ransomware Expansion BlackBerry and Microsoft documented RomCom’s transition from Cuba ransomware to Underground ransomware in late 2023, with Underground continuing operations through 2025-2026. Underground maintains a leak site and targets a broader range of sectors than the original Cuba operations, with confirmed victims in media, IT services, and manufacturing alongside the continued targeting of US organisations.


Defensive Implications

Phishing Lure Awareness RomCom invests in contextually appropriate lures — events, crises, and policy topics relevant to the specific targets they’re pursuing. For government and defence sector organisations, this means training and processes around document opening from expected external contacts must account for the possibility that documents from expected sources may themselves be trojanised. Email gateway scanning alone is insufficient; detonation sandboxing and CDR (content disarm and reconstruction) should be applied to all inbound documents from external parties.

Browser and OS Patch Cadence The October 2023 campaign exploited a Firefox vulnerability that Mozilla patched within 24 hours of responsible disclosure. Organisations relying on monthly or quarterly patching cycles would have had a months-long exposure window. Browser vulnerabilities exploited in zero-day campaigns require emergency patch deployment, not routine cadence. The same applies to Windows SmartScreen and other OS-level security control bypasses.

SnipBot Detection The modular SnipBot architecture complicates static detection — the initial loader may be benign-looking, with malicious functionality loaded remotely. Detection should focus on:

  • Unusual parent-child process relationships involving known RomCom indicators
  • Encrypted communications to newly registered or unusual domains from document-opening processes (Word, Acrobat launching network connections)
  • Plugin files written to user-writable directories (AppData, Temp) with unusual naming conventions
  • COM object instantiation from Office processes as a persistence/execution indicator

ESET’s SnipBot analysis provides YARA rules covering known loader characteristics.

Network Infrastructure Indicators RomCom infrastructure clusters around specific hosting providers and naming patterns. The group consistently uses typosquatted or themed domain names (e.g., update-microsoft[.]io, ua-gov[.]info). OSINT-based domain monitoring and blocking based on registrar, nameserver, and hosting provider patterns can provide some lead time before IOC lists are published.

Insider Knowledge of Events and Contacts The targeting precision in RomCom campaigns — lures that reference specific events, documents that appear to originate from known contacts — suggests that some initial access may occur through prior breaches that expose address books and calendars. Organisations with known exposure in previous breaches should treat the risk of targeted follow-on phishing from those contacts as elevated.


The Hybrid Model Problem

RomCom’s dual mandate creates a strategic complication for defenders and for Western governments. Criminal ransomware operations are treated as law enforcement matters; state-sponsored espionage triggers different legal authorities and response options. When the same actors, using the same infrastructure and implants, conduct both types of activity — sometimes within the same intrusion — the categorisation becomes both difficult and consequential for response.

The hybrid model also allows Russia to maintain plausible distance from the espionage component. When RomCom conducts ransomware operations, the group functions as organised crime — which Russia does not officially sanction or enable. The criminal activity provides cover for the intelligence collection that occurs alongside it. Disrupting this requires treating the entire operational ecosystem as a unified threat, regardless of whether a specific incident was “criminal” or “state-sponsored.”

For private sector defenders, that distinction is largely irrelevant. An SnipBot implant quietly collecting pharmaceutical R&D is a threat regardless of whether the collection serves GRU priorities or criminal intelligence brokerage. The control requirements are the same; the urgency is the same.