PULSE NAME
Unattributed RomCom Threat Actor Spoofing Popular Apps Now Hits Ukrainian Militaries
WHITE AlienVault 2022-10-24 Modified: 2022-11-23
12
IOCs
MEDIUM VOLUME
A previously unknown RomCom RAT threat actor is now targeting Ukrainian military institutions, BlackBerry Research and Intelligence has revealed in a series of images and video clips from the past two months, as well as the recent attacks on Ukrainian government institutions.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
RomCom
Indicators of Compromise (12)
All FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 05681ff7cae6b28f5714628a269caa5115da49c94737ce82ec09b4312e40fd26 2022-10-24
FileHash-SHA256 068117b406940ac510ed59efd1d7c7651f645a31bd70db6de16aba12c055aae6 2022-10-24
FileHash-SHA256 3e3a7116eeadf99963077dc87680952cca87ff4fe60a552041a2def6b45cbeea 2022-10-24
FileHash-SHA256 4fc9202ff84ef84b8c5e6140b66ac3d04570daf886a7f1ae31661ade882f963e 2022-10-24
FileHash-SHA256 9f61259c966f34d89b70af92b430ae40dd5f1314ee6640d16e0b7b0f4f385738 2022-10-24
FileHash-SHA256 a2511c5c2839bfbdf9c0f84f415d5eae168456e5d3f77f1becdbcd69fba4daa4 2022-10-24
FileHash-SHA256 e80d80521238008bf6f429e072eaf6030c06e2d3123d03ea9b36f5a232a1ec90 2022-10-24
domain 4qzm.com 2022-10-24
domain advanced-ip-scaner.com 2022-10-24
domain advanced-ip-scanners.com 2022-10-24
domain notfiled.com 2022-10-24
domain optasko.com 2022-10-24