{"id":5043,"date":"2025-07-02T10:03:42","date_gmt":"2025-07-02T10:03:42","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/02\/ta829-hackers-employs-new-ttps-and-upgraded-romcom-backdoor-to-evade-detections\/"},"modified":"2025-07-02T10:03:42","modified_gmt":"2025-07-02T10:03:42","slug":"ta829-hackers-employs-new-ttps-and-upgraded-romcom-backdoor-to-evade-detections","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/02\/ta829-hackers-employs-new-ttps-and-upgraded-romcom-backdoor-to-evade-detections\/","title":{"rendered":"TA829 Hackers Employs New TTPs and Upgraded RomCom Backdoor to Evade Detections"},"content":{"rendered":"<p>    TA829 Hackers Employs New TTPs and Upgraded RomCom Backdoor to Evade Detections<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The cybersecurity landscape faces a renewed threat as TA829, a sophisticated threat actor group, has emerged with enhanced tactics, techniques, and procedures (TTPs) alongside an upgraded version of the notorious RomCom backdoor.<\/p>\n<p>This hybrid cybercriminal-espionage group has demonstrated remarkable adaptability, conducting both financially motivated attacks and state-aligned espionage operations, particularly following the invasion of Ukraine.<\/p>\n<p>The actor\u2019s unique positioning in the threat ecosystem represents a concerning evolution in modern cyber warfare, where traditional boundaries between cybercrime and espionage continue to blur.<\/p>\n<p>TA829\u2019s attack methodology centers on highly targeted <a href=\"https:\/\/cybersecuritynews.com\/evolving-phishing-campaigns\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing campaigns<\/a> that leverage compromised MikroTik routers operating as REM Proxy services.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgic01SOpTnaJnfVwP1dxxhr8nhyhEJKLFYmYxFBpyFg051RBsnf2GZb4HgZAulZG3NEb2CiBrXJy6h-8nWp2Q5pkCISZ0QOnpVeaHVn-Ye0MKS4aXWFvq4xrL9g-WuBv3rt4f9QL_wu9dwurFOshjGwRlWOaquDurtdNGtLYzDAo-BRQ8jbsz_h3hjY68\/s16000\/Delivery%2520and%2520installation%2520for%2520the%2520UNK_GreenSec%2520and%2520TA829%2520%28Source%2520-%2520Proofpoint%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Delivery and installation for the UNK_GreenSec and TA829 (Source \u2013 Proofpoint)<\/figcaption><\/figure>\n<\/div>\n<p>These compromised devices, typically hosting SSH services on port 51922, serve as upstream infrastructure for relaying malicious traffic through newly created accounts at freemail providers.<\/p>\n<p>The group\u2019s email campaigns feature plaintext messages with generic job-seeking or complaint themes, each containing unique links that route targets through elaborate redirection chains before delivering the malicious payload.<\/p>\n<p>The group\u2019s arsenal includes several sophisticated <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> variants, with the upgraded RomCom backdoor now manifesting as SingleCamper and DustyHammock.<\/p>\n<p>Proofpoint researchers <a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/10-things-i-hate-about-attribution-romcom-vs-transferloader\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> these variants as part of TA829\u2019s regularly updated suite of tools, noting their integration into a unified infection management system.<\/p>\n<p>The malware demonstrates advanced evasion capabilities through registry-based operations and sophisticated anti-analysis techniques.<\/p>\n<p>Following initial infection through phishing emails that spoof OneDrive or Google Drive interfaces, victims unknowingly download the SlipScreen loader, which serves as the first stage of the infection chain.<\/p>\n<p>This loader, often signed with fraudulent certificates and disguised with PDF reader icons, implements multiple detection evasion mechanisms.<\/p>\n<p>The malware performs critical registry checks to ensure the targeted system contains at least 55 recent documents, effectively avoiding sandbox environments that typically lack such user activity traces.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Advanced Registry-Based Persistence Mechanism<\/strong><\/h2>\n<p>The most notable evolution in TA829\u2019s upgraded RomCom backdoor lies in its sophisticated registry-based persistence mechanism.<\/p>\n<p>The SlipScreen loader decrypts and executes shellcode directly within its memory space, initiating communications with command and control servers only after successful environmental validation.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh15QFoZ0waOYK0gfPadueoleCpx2_NDZ2NE4MkK3FMJb98pRzgNUFAcPaNd_iHxHHI0wqLJG6E5Gx0S-acBNrm-CqFoHHyvgZhWFcsdTyZdfXuv6RkS_dWX71lAWjbCl9ZlwzRVokAsAd3OoY7SQdtU_7vIVSamgaxYnCYOSvH7ER80RrbGIUYbfVeXWg\/s16000\/TA829%2520download%2520JavaScript%2520%28Source%2520-%2520Proofpoint%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">TA829 download JavaScript (Source \u2013 Proofpoint)<\/figcaption><\/figure>\n<\/div>\n<p>Upon verification, the system downloads additional components including RustyClaw or MeltingClaw loaders, which establish persistence through COM hijacking techniques.<\/p>\n<p>The persistence mechanism involves manipulating specific registry keys such as <code>SOFTWAREClassesCLSID{2155fee3-2419-4373-b102-6843707eb41f}InprocServer32<\/code>, allowing the malware to survive system reboots by executing during explorer.exe restarts.<\/p>\n<p>This technique effectively embeds the malware deep within the Windows operating system\u2019s core processes, making detection and removal significantly more challenging for traditional security solutions.<\/p>\n<p>The registry-based approach also enables the malware to store encrypted payloads across multiple registry locations, further complicating <a href=\"https:\/\/cybersecuritynews.com\/free-forensic-investigation-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">forensic analysis<\/a> efforts.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\">Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=braodo_stealer&amp;utm_content=demo_1&amp;utm_term=250625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>Try ANY.RUN now<\/strong><\/a><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/ta829-hackers-employs-new-ttps\/\">TA829 Hackers Employs New TTPs and Upgraded RomCom Backdoor to Evade Detections<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/ta829-hackers-employs-new-ttps\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>TA829 Hackers Employs New TTPs and Upgraded RomCom Backdoor to Evade Detections The cybersecurity landscape faces a renewed threat as TA829, a sophisticated threat actor group, has emerged with enhanced tactics, techniques, and procedures (TTPs) alongside an upgraded version of the notorious RomCom backdoor. This hybrid cybercriminal-espionage group has demonstrated remarkable adaptability, conducting both financially [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-5043","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5043"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5043"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5043\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5043"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5043"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5043"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}