EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Avviso tecnico

10 Things I Hate About Attribution: RomCom vs. TransferLoader

Fonte aperta verificata
Intelligence con provenienza tracciabile. EudorIA conserva gli indicatori tecnici acquisiti dai feed supportati, con fonte, data e contesto. Gli IOC condivisibili sono disponibili nei feed STIX; le azioni di rilevamento e blocco richiedono la valutazione di validita, confidenza e applicabilita al perimetro del cliente. Consulta i feed STIX
Sintesi operativa EudorIA

Cosa significa

Priorità 55/100

MISP EudorIA ha pubblicato l'advisory "10 Things I Hate About Attribution: RomCom vs. TransferLoader". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.

Perché conta

Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.

DestinatariITSOCCISO

Testo acquisito dalla fonte

Evento MISP pubblicato con TLP:CLEAR: 10 Things I Hate About Attribution: RomCom vs. TransferLoader. Report from - [URL rimossa] (1745170857) ### Key takeaways * TA829 conducts a mixture of espionage and cybercriminal operations, which rely on services sourced from the criminal underground, and a regularly updated suite of tools built upon the legacy RomCom backdoor. * While tracking TA829, Proofpoint observed a highly similar email campaign and redirection infrastructure set-up. This similar campaign deployed a new loader and backdoor dubbed TransferLoader, which Proofpoint currently attributes to a separate cybercriminal cluster called “UNK\_GreenSec”, rather than TA829. * This blog will show how analysts explored the differences and overlaps between both sets of activity and leave an open-ended question around the relationship between these two clusters within the larger criminal and espionage ecosystem. ### Overview Most of the time, delineating activities from distinct clusters and separating cybercrime from espionage can be done based on differing tactics, techniques, and procedures (TTPs), tooling, volume/scale, and targeting. However, in the case of TA829 and a cluster Proofpoint dubbed “UNK\_GreenSec”, there is more ambiguity. TA829 is a cybercriminal actor that occasionally also conducts espionage aligned with Russian state interests, while UNK\_GreenSec is an unusual cybercriminal cluster. TA829 overlaps with activity tracked by third-parties as RomCom, Void Rabisu,

Fonte
MISP EudorIA
Entità pubblicatrice
MISP EudorIA
Tipo entità
Comunità di intelligence
Area
Global
Lingua originale
it · traduzione non necessaria
Pubblicazione
30/07/2026 02:52
Condivisione
TLP:CLEAR
Indicatori dichiarati dalla fonte
124
IOC indicizzati per la ricerca
0 valori nel periodo di conservazione
IOC disponibili nel feed STIX
124Ultima verifica di condivisione: 2026-09-26T05:00:58.203767+00:00
Evento MISP
31de44de-304f-48c4-8ca0-38d1da0b8eba
MITRE ATT&CK
Spearphishing Link - T1566.002
Classificazione
Media
Gruppo attribuito dalla fonte
RomCom
Apri la fonte originale