
A new advisory from the BlackBerry Research & Intelligence Team revealed that the threat actor, RomCom, has been weaponizing SolarWinds Network Performance Monitor, KeePass Password Manager, and PDF Reader Pro in a series of new attack campaigns against targets in Ukraine and English-speaking countries, including the United Kingdom.
The advisory said that new attack campaigns take advantage of these products’ brand power. The team uncovered the campaigns while analyzing network artifacts, targeting Ukrainian military organizations through spoofed versions of Advanced IP Scanner software.
The team uncovered spoofed KeePass and PDF Reader Pro websites in the Ukrainian language. Based on the analysis of the terms of service (TOS) of these websites and the SSL certificates of command-and-control (C2), the team believes that some English-speaking countries are targeted, including the United Kingdom, although Ukraine appears to be the primary target.
RomCom followed a straightforward plan to get ready for an attack: stealing the original legitimate HTML code from the vendor to spoof; registering a malicious domain that looks similar to the legitimate one; Trojanizing an application; uploading a malicious bundle to the decoy website; sending targeted phishing emails to the victims; or, in some cases, using additional infector vectors.
According to BlackBerry, these techniques indicate a connection between the RomCom and the Cuba ransomware and Industrial Spy, a relatively new ransomware group that emerged in April 2022. A list of RomCom RAT Indicators of Compromise (IoCs) is available in the original text of the BlackBerry advisory.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543