⤷ Title: Nebulous Mantis Cyber Espionage Group: RomCom RAT and Hybrid Tactics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 03 May 2025 00:10:29 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #APT #cyber attack #cyber_espionage #Hacking #Nebulous Mantis #ransomware #RomCom RAT #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 03 May 2025 00:10:29 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #APT #cyber attack #cyber_espionage #Hacking #Nebulous Mantis #ransomware #RomCom RAT #threat intelligence
Daily CyberSecurity
Nebulous Mantis Cyber Espionage Group: RomCom RAT and Hybrid Tactics
PRODAFT report details Nebulous Mantis (Cuba/STORM-0978), a Russian-speaking group using RomCom RAT for espionage and ransomware.
⤷ Title: Bridewell Uncovers ‘Operation Deceptive Prospect’ Targeting UK Organizations via Feedback Portals
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 May 2025 00:40:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI_Generated Lures #Espionage Campaign #Feedback Form Phishing #RomCom backdoor #SnipBot #UK Critical Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 05 May 2025 00:40:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI_Generated Lures #Espionage Campaign #Feedback Form Phishing #RomCom backdoor #SnipBot #UK Critical Infrastructure
Daily CyberSecurity
Bridewell Uncovers ‘Operation Deceptive Prospect’ Targeting UK Organizations via Feedback Portals
Bridewell uncovers Operation Deceptive Prospect, a RomCom campaign using fake customer feedback to deliver malware via spoofed cloud storage links.
⤷ Title: Proofpoint Exposes TA829 & UNK_GreenSec’s Dual-Nature Campaigns
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:52:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #Cybercriminal Overlap #Espionage #Morpheus ransomware #Proofpoint #RomCom #Russian APT #TA829 #threat intelligence #TransferLoader #UNK_GreenSec
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 01 Jul 2025 00:52:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #Cybercriminal Overlap #Espionage #Morpheus ransomware #Proofpoint #RomCom #Russian APT #TA829 #threat intelligence #TransferLoader #UNK_GreenSec
Daily CyberSecurity
Proofpoint Exposes TA829 & UNK_GreenSec's Dual-Nature Campaigns
Proofpoint reveals two Russian threat clusters (TA829 & UNK_GreenSec) blending financial cybercrime with state-aligned espionage, using RomCom and TransferLoader malware.
⤷ Title: WinRAR Zero-Day CVE-2025-8088 Exploited to Spread RomCom Malware
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 14:46:10 +0000
════════════════════════
⌗ Tags: #Security #0day #Cyber Attack #Cybersecurity #eset #Malware #RomCom #Russia #Vulnerability #WinRAR
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sat, 09 Aug 2025 14:46:10 +0000
════════════════════════
⌗ Tags: #Security #0day #Cyber Attack #Cybersecurity #eset #Malware #RomCom #Russia #Vulnerability #WinRAR
Hackread
WinRAR Zero-Day CVE-2025-8088 Exploited to Spread RomCom Malware
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Hackers Exploited a New WinRAR Flaw Before It Was Patched
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 08:31:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #ESET #malware #phishing #RomCom #vulnerability #Winrar
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 08:31:05 +0000
════════════════════════
⌗ Tags: #Vulnerability #cybersecurity #ESET #malware #phishing #RomCom #vulnerability #Winrar
Penetration Testing Tools
Hackers Exploited a New WinRAR Flaw Before It Was Patched
A new WinRAR vulnerability (CVE-2025-8088) was exploited in the wild by the RomCom group before a patch was available. Users are urged to update to v7.13.
⤷ Title: WinRAR Zero-Day (CVE-2025-8088) Exploited by RomCom Hackers, ESET Warns
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 13 Aug 2025 07:47:24 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_8088 #Cyber Espionage #cybersecurity #ESET #malware #path traversal #RomCom #Winrar #zero_day
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 13 Aug 2025 07:47:24 +0000
════════════════════════
⌗ Tags: #Vulnerability #CVE_2025_8088 #Cyber Espionage #cybersecurity #ESET #malware #path traversal #RomCom #Winrar #zero_day
Penetration Testing Tools
WinRAR Zero-Day (CVE-2025-8088) Exploited by RomCom Hackers, ESET Warns
A new WinRAR zero-day vulnerability (CVE-2025-8088) is being exploited by the RomCom cyber-espionage group to deploy malware via malicious archives. Update to v7.13 now.
⤷ Title: GRU Unit 29155 Uses SocGholish to Target US Firm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 02:14:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Arctic Wolf Labs #cyber_espionage #GRU Unit 29155 #Malware_as_a_Service #Mythic Agent #RomCom #russia #SocGholish #TA569 #Ukraine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 02:14:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Arctic Wolf Labs #cyber_espionage #GRU Unit 29155 #Malware_as_a_Service #Mythic Agent #RomCom #russia #SocGholish #TA569 #Ukraine
Daily CyberSecurity
GRU Unit 29155 Uses SocGholish to Target US Firm
Arctic Wolf Labs reveals Russian GRU Unit 29155 using SocGholish to deploy RomCom malware against a US firm with ties to Ukraine.
⤷ Title: SHADOW-VOID-042 Impersonates Trend Micro in Phishing Campaign to Breach Critical Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:38:38 +0000
════════════════════════
⌗ Tags: #Cyber Security #Critical Infrastructure #Impersonation #phishing #RomCom #SHADOW_VOID_042 #spear_phishing #Trend Micro #Void Rabisu
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 15 Dec 2025 00:38:38 +0000
════════════════════════
⌗ Tags: #Cyber Security #Critical Infrastructure #Impersonation #phishing #RomCom #SHADOW_VOID_042 #spear_phishing #Trend Micro #Void Rabisu
Daily CyberSecurity
SHADOW-VOID-042 Impersonates Trend Micro in Phishing Campaign to Breach Critical Infrastructure
SHADOW-VOID-042 impersonated Trend Micro via fake security advisories to breach defense, energy, and chemical firms. Tactics align with Void Rabisu (ROMCOM), using HR lures and targeted exploits.
⤷ Title: Hackers Still Using Patched WinRAR Flaw for Malware Drops, Warns Google
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 15:49:23 +0000
════════════════════════
⌗ Tags: #Malware #Security #backdoor #Carpathian #Cybersecurity #Google #GTIG #Poison Ivy #RomCom #Russia #Stockstay #Vulnerability #WinRAR
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 28 Jan 2026 15:49:23 +0000
════════════════════════
⌗ Tags: #Malware #Security #backdoor #Carpathian #Cybersecurity #Google #GTIG #Poison Ivy #RomCom #Russia #Stockstay #Vulnerability #WinRAR
Hackread
Hackers Still Using Patched WinRAR Flaw for Malware Drops, Warns Google
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: The Persistence of WinRAR: Google Warns of Widespread CVE-2025-8088 Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 04:15:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability #Ads #CVE_2025_8088 #Google Threat Intelligence #InfoSec 2026 #path traversal #phishing #RomCom #Sandworm #Startup Persistence #Winrar
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 29 Jan 2026 04:15:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Vulnerability #Ads #CVE_2025_8088 #Google Threat Intelligence #InfoSec 2026 #path traversal #phishing #RomCom #Sandworm #Startup Persistence #Winrar
Penetration Testing Tools
The Persistence of WinRAR: Google Warns of Widespread CVE-2025-8088 Attacks
The Google Threat Intelligence Group (GTIG) has disclosed the extensive exploitation of a critical vulnerability, designated CVE-2025-8088, residing