10 Things I Hate About Attribution: RomCom vs. TransferLoader
· Published 01/07/2025 08:07 · Modified 01/07/2025 08:36
Essential information
- Published
- 01/07/2025 08:07
- Modified
- 01/07/2025 08:36
- Tags
- 2025-07-01 dustyhammock hellcat meltingclaw morpheus ransomware romcom rustyclaw shadyhammock singlecamper slipscreen transferloader
- Related entities
- 103 observables, 1 intrusion sets (apt), 19 techniques (mitre), 9 malware, 7 others
Description
This report analyzes the activities of two threat actor clusters: TA829 and UNK_GreenSec. TA829 conducts both espionage and cybercrime operations using tools like SingleCamper and DustyHammock. UNK_GreenSec deploys TransferLoader malware leading to ransomware infections. The actors share similarities in infrastructure, delivery tactics, and lure themes, raising questions about their relationship. Four hypotheses are presented regarding their potential connection, ranging from shared third-party services to being the same actor. The report highlights the increasing overlap between cybercrime and espionage activities, making attribution more challenging in the current threat landscape.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Observables (103)
ms.share-onedr.comworkspace-doc.livetemptransfer.livesupportcausems.comsite-staff.saleshare-pdf.liveshare-doc.livepdfshare.clickonlinedrive.clickopendnsapi.netonestorelink.liveonelivedrv.comonefile.socialonedrivems.worksonedrweb.liveonedrivems.cloudonedrivecloud.netonedrivecloud.liveonedrivecloud.expertonedrivecloud.clickonedr.expertondv.liveondrve.livemyonedrive365.livemydrv1.livemy1drv.livemy1drv.onlinemsvhost.commy-356drv.onlinemspdf.livemngersrv.comlivestorage.clicklauradream.comhealthfy.biogworkspace.socialgdrvdocs.onlinegdrive-share.onlinegdl-cloud.worksfile-share.worksfile-acess.livedvcloud.livedrsync.clickdrshare.onlinedrivestorage.onlinedrivepublic.livedrivehub.livedrivehost.livedrivedefend.comdr365.livediskstorage.clickdocumentapproved.clickdeliverycitylife.comdatadrv1.comd1rv.socialdata-dv.liveconsvcprivacy.comcloudly.liveclouderive.comcloud1dv.comcloud-pdf.onlinecdngateway.us365work.chat365msdrv.live365drv.live1dvstorage.com1dv365.live1drvms.space1drw.live1drvfiles.online1drv365.online1drvcloud.online1drv365.live1drv.zone1drv.site1drv.world1drv.me1drv-team.works1drv.biz1drivems.works1drivecloud.click1drivecloud.live1drivems.expert1drive.works1drive.expert1drive.social1drive-work.online1drive.bio1dcloud.live1day.livefba9f2c351e898bfc61c8b1181020212ccb9e55041c4dd433ca2867dbf796469f5f2761278163a1a813356666cb305fe37806f5f633b2a5475997f10d24fb3d4e7917ff12114be5c79ca9bd0082eb628192c2ebfbee7aad2ae626ea208ee37cfcd526475391c375e8e40f0146146672928db9bbf210acb41e0fd41381cd5eb9a8f3b065e6aa6bc220867cdcb1c250c69b2d46422c51f66f25091f6cab5d043de7fc65b23e0a85f548e4268b77b66a3c9f3d08b9c1817c99bc1336d51d36e1ec66d5226cba687d99ce14eda8de290edd470e79436625618559c8db1458a53666c7e51eb44cfd945f4a155707f773fae3207ebfb59d45ea866ba69bd9bc28dfc3254a94c7ec259104478b40fd0e6325d1f5364351e6ce1adfd79369d6438ed6ed93a234b49b834849689da477f77ca6363b40ee83e58213ee51b1ec248da90a54333971df8f5c34c3c79f64e2e28e300260499285bd37f77295ba88897728ace4b1c6a5476d485d311be1e07c2e0d2ae322214caa5d4f84398d4169d499105b01a00385cae3630694eb70e2b82d5baa6130c503126c17db3fc63376c7d28c0414507b9e353239c4c057115e8871adc3cfb42467998c6b737b28435ecc9405001c9
Intrusion sets (APT) (1)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 14:36 · Modified 21/12/2025 14:36
Techniques (MITRE) (19)
-
Dead Drop Resolver
-
Malware
-
Domains
-
Malware
-
Bidirectional Communication
-
Tool
-
Rundll32
-
Software Packing
-
Registry Run Keys / Startup Folder
-
Query Registry
-
Web Protocols
-
System Network Configuration Discovery
-
System Information Discovery
-
Process Discovery
-
Ingress Tool Transfer
-
Deobfuscate/Decode Files or Information
-
Obfuscated Files or Information
-
Modify Registry
-
Command and Scripting Interpreter
Malware (9)
-
FamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
-
FamilyPublished 25/09/2025 09:21 · Modified 25/09/2025 09:21
-
FamilyPublished 25/09/2025 09:21 · Modified 25/09/2025 09:21
-
FamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
-
FamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
-
FamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
-
FamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
-
FamilyPublished 15/09/2025 18:00 · Modified 15/09/2025 18:00
-
FamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
Others (7)
- Ukraine
- United States of America
- Defense
- sharepdf.limited
- journalctl.website
- file-cloud.company
- 1share.limited