PULSE NAME
Russian RomCom Utilizing SocGholish to Deliver Mythic Agent to U.S. Companies Supporting Ukraine
WHITE RomCom AlienVault 2025-11-25 Modified: 2025-12-25
17
IOCs
MEDIUM VOLUME
Arctic Wolf Labs identified a U.S.-based company targeted by the Russian-aligned threat group RomCom via SocGholish, operated by TA569. This marks the first observed instance of a RomCom payload being distributed through SocGholish. The attack chain involved compromising legitimate websites, using fake update lures to deliver malware, and executing malicious JavaScript on victim hosts. The targeted company had ties to Ukraine, aligning with RomCom's focus on entities supporting Ukraine. Evidence suggests Russia's GRU unit 29155 is leveraging SocGholish for targeting. The attack was thwarted by Arctic Wolf's Aurora Endpoint Defense, which detected and quarantined the RomCom loader upon delivery.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
SocGholish FAKEUPDATE VIPERTUNNEL Mythic Agent
Indicators of Compromise (17)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2025-64446 2025-11-25
FileHash-MD5 9912bb2d82218ba504c28e96816315b3 2025-11-25
FileHash-SHA1 991a247a432e782f9a46ba1432708848dab91a23 2025-11-25
FileHash-SHA256 f7605fc8a1ee5f21aec55da04dbaa95a05db95b5e7851b172a5d30c7fb1da885 2025-11-25
domain basilic.info 2025-11-25
domain carnesmemdesa.com 2025-11-25
domain imprimerie-agp.com 2025-11-25
domain orlandoscreenenclosure.net 2025-11-25
domain ozivoice.com 2025-11-25
domain smashingboss.com 2025-11-25
domain solarrayes.com 2025-11-25
domain srlaptop.com 2025-11-25
domain withheldforprivacy.com 2025-11-25
hostname africa.thesmalladventureguide.com 2025-11-25
hostname email.smashingboss.com 2025-11-25
hostname realty.yourpgcountyliving.com 2025-11-25
hostname virtual.urban-orthodontics.com 2025-11-25