← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Russian RomCom Utilizing SocGholish to Deliver Mythic Agent to U.S. Companies Supporting Ukraine
The recent identification of a U.S.-based company targeted by the Russian-aligned threat group RomCom, utilizing the SocGholish malware framework, underscores an evolving cyber threat landscape. This incident marks the first recorded use of a RomCom payload distributed via SocGholish, a technique generally operated by the threat actor TA569, known for its financially motivated attacks.
In September 2025, a sequence of events unfolded where, approximately 10 minutes after an initial exploitation via the familiar SocGholish attack chain, the RomCom payload identified as a Mythic Agent loader was delivered to the compromised system. SocGholish has a history as a malware delivery mechanism, primarily distributing a fake software update lure that exploits compromised legitimate websites to inject malicious JavaScript. When successful, this method allows the installation of loaders that further fetch additional payloads, facilitating long-term access to the affected network.
MITRE ATT&CK & Malware Families
Indicators of Compromise (17)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| CVE | CVE-2025-64446 | — | 2025-11-26 | |
| FileHash-MD5 | 9912bb2d82218ba504c28e96816315b3 | MD5 of f7605fc8a1ee5f21aec55da04dbaa95a05db95b5e7851b172a5d30c7fb1da885 | 2025-11-26 | |
| FileHash-SHA1 | 991a247a432e782f9a46ba1432708848dab91a23 | SHA1 of f7605fc8a1ee5f21aec55da04dbaa95a05db95b5e7851b172a5d30c7fb1da885 | 2025-11-26 | |
| FileHash-SHA256 | f7605fc8a1ee5f21aec55da04dbaa95a05db95b5e7851b172a5d30c7fb1da885 | — | 2025-11-26 | |
| domain | basilic.info | — | 2025-11-26 | |
| domain | carnesmemdesa.com | — | 2025-11-26 | |
| domain | imprimerie-agp.com | — | 2025-11-26 | |
| domain | orlandoscreenenclosure.net | — | 2025-11-26 | |
| domain | ozivoice.com | — | 2025-11-26 | |
| domain | smashingboss.com | — | 2025-11-26 | |
| domain | solarrayes.com | — | 2025-11-26 | |
| domain | srlaptop.com | — | 2025-11-26 | |
| domain | withheldforprivacy.com | — | 2025-11-26 | |
| hostname | africa.thesmalladventureguide.com | — | 2025-11-26 | |
| hostname | email.smashingboss.com | — | 2025-11-26 | |
| hostname | realty.yourpgcountyliving.com | — | 2025-11-26 | |
| hostname | virtual.urban-orthodontics.com | — | 2025-11-26 |