Skip to content
← All Threat Actors
Nation-State high Russia

RomCom / Storm-0978 (Russia)

Russian cybercrime/espionage hybrid (formal state relationship assessed, not publicly confirmed) · Dual mandate: financial (Underground ransomware) and state-directed intelligence collection (espionage against NATO and Ukraine)

Reports 1
Active Since 2020
Last Reported 25 Jun 2026
Sectors Targeted government, defense, technology, healthcare, financial-services

Tactics, Techniques & Procedures (TTPs)

  • Firefox zero-day exploitation (CVE-2024-9680, no user interaction required) combined with Windows privilege escalation zero-day — one of few criminal groups with confirmed zero-day development
  • SnipBot modular backdoor (2024): file theft, command execution, process management with minimal footprint
  • PEAPOD RAT (2023): lightweight persistent access for targeted espionage against specific high-value individuals
  • Underground ransomware operations — criminal extortion alongside intelligence tasking from same infrastructure
  • Trojanised software mimicking legitimate tools (Advanced IP Scanner, PDF readers, KeePass) for initial access
  • Precision social engineering against specific NATO event attendees and political targets
  • Exploitation of Windows zero-days for privilege escalation in espionage chain

Known Targets

Ukrainian government ministries and military entitiesNATO member state governments (Poland, Czech Republic, Germany)Defence contractors and defence industry organisationsFinancial institutions and pharmaceutical companies (Underground ransomware component)Western government officials and political targets

Analyst Notes

RomCom simultaneously conducts state-directed espionage against NATO and Ukrainian targets while running Underground ransomware operations for financial gain — a rare criminal/intelligence hybrid. The Firefox+Windows zero-day chain (2024) placed RomCom among a small group of criminal actors with confirmed zero-day development capability. Both tracks (SnipBot espionage and Underground ransomware) operate from the same infrastructure with different objectives, suggesting either state tasking alongside freelance criminal activity or a state contractor model. Ukraine and NATO targeting clearly serves Russian intelligence priorities.

Also Known As

Storm-0978 (Microsoft)Tropical Scorpius (CrowdStrike)UNC2596 (Mandiant)UAC-0180