RomCom is a apt_group tracked across 6 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed November 25, 2025; most recent activity June 30, 2026.
Two Russia-aligned cyber campaigns are exploiting the WinRAR vulnerability CVE-2025-8088 against Ukrainian targets nearly a year after it was patched. The flaw, a path traversal vulnerability, allows attackers to write…
The CVE-2025-8088 vulnerability in WinRAR is being exploited by various threat actors for initial access and to deploy malware. The flaw allows attackers to use Alternate Data Streams to write malicious files to…
In November 2025, a spear-phishing campaign utilizing Trend Micro-themed lures targeted various sectors, including energy, defense, pharmaceuticals, and cybersecurity. The campaign was detected and mitigated by the…
Cybersecurity researchers at Arctic Wolf Labs have identified a cyberattack campaign utilizing fake browser update notifications to distribute SocGholish malware. This campaign is linked to Russian threat actors and…
A series of cyberattacks targeting a US engineering firm has been attributed to Russian cyber groups. The attackers utilized SocGholish and RomCom tools, which are commonly associated with cybercrime, to obscure their…
A U.S.-based civil engineering firm was attacked by the Russia-aligned threat group RomCom, which utilized SocGholish malware in a September attack. The attack is believed to be connected to the firm's work for a U.S.…