PULSE NAME
RomCom Threat Actor Abuses KeePass and SolarWinds to Target Ukraine and Potentially the United Kingdom
WHITE AlienVault 2022-11-03 Modified: 2022-11-03
21
IOCs
MEDIUM VOLUME
A threat actor known as RomCom is targeting UK-speaking countries, including the United Kingdom, through spoofed versions of SolarWinds, KeePass and PDF Reader Pro, according to BlackBerry.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
RomCom
Indicators of Compromise (9 / 21 total)
All FileHash-MD5 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1a21a1e626fd342e794bcc3b06981d2c 2022-11-03
FileHash-MD5 4e4eca58b896bdb6db260f21edc7760a 2022-11-03
FileHash-MD5 550f42c5b555893d171285dc8b15b4b5 2022-11-03
FileHash-MD5 6310a2063687800559ae9d65cff21b0a 2022-11-03
FileHash-MD5 7c003b4f8b3c0ab0c3f8cb933e93d301 2022-11-03
FileHash-MD5 8284421bbb94f3c37f94899cdcd19afd 2022-11-03
FileHash-MD5 a7172aef66bb12e1bb40a557bb41e607 2022-11-03
FileHash-MD5 cb933f1c913144a8ca6cfcfd913d6d28 2022-11-03
FileHash-MD5 d1a84706767bfb802632a262912e95a8 2022-11-03