PULSE NAME
Russian RomCom Utilizing SocGholish to Deliver Mythic Agent to U.S. Companies Supporting Ukraine
WHITE RomCom PetrP.73 2025-11-26 Modified: 2025-12-26
17
IOCs
MEDIUM VOLUME
The recent identification of a U.S.-based company targeted by the Russian-aligned threat group RomCom, utilizing the SocGholish malware framework, underscores an evolving cyber threat landscape. This incident marks the first recorded use of a RomCom payload distributed via SocGholish, a technique generally operated by the threat actor TA569, known for its financially motivated attacks. In September 2025, a sequence of events unfolded where, approximately 10 minutes after an initial exploitation via the familiar SocGholish attack chain, the RomCom payload identified as a Mythic Agent loader was delivered to the compromised system. SocGholish has a history as a malware delivery mechanism, primarily distributing a fake software update lure that exploits compromised legitimate websites to inject malicious JavaScript. When successful, this method allows the installation of loaders that further fetch additional payloads, facilitating long-term access to the affected network.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Dridex SocGholish FAKEUPDATE VIPERTUNNEL RomCom
Indicators of Compromise (17)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2025-64446 2025-11-26
FileHash-MD5 9912bb2d82218ba504c28e96816315b3 MD5 of f7605fc8a1ee5f21aec55da04dbaa95a05db95b5e7851b172a5d30c7fb1da885 2025-11-26
FileHash-SHA1 991a247a432e782f9a46ba1432708848dab91a23 SHA1 of f7605fc8a1ee5f21aec55da04dbaa95a05db95b5e7851b172a5d30c7fb1da885 2025-11-26
FileHash-SHA256 f7605fc8a1ee5f21aec55da04dbaa95a05db95b5e7851b172a5d30c7fb1da885 2025-11-26
domain basilic.info 2025-11-26
domain carnesmemdesa.com 2025-11-26
domain imprimerie-agp.com 2025-11-26
domain orlandoscreenenclosure.net 2025-11-26
domain ozivoice.com 2025-11-26
domain smashingboss.com 2025-11-26
domain solarrayes.com 2025-11-26
domain srlaptop.com 2025-11-26
domain withheldforprivacy.com 2025-11-26
hostname africa.thesmalladventureguide.com 2025-11-26
hostname email.smashingboss.com 2025-11-26
hostname realty.yourpgcountyliving.com 2025-11-26
hostname virtual.urban-orthodontics.com 2025-11-26