ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

RomCom weaponizes KeePass and SolarWinds to target Ukraine, potentially the UK

A new advisory from the BlackBerry Research & Intelligence Team revealed that the threat actor, RomCom, has been weaponizing SolarWinds Network Performance Monitor, KeePass Password Manager, and PDF Reader Pro in a series of new attack campaigns against targets in Ukraine and English-speaking countries, including the United Kingdom.

 

The advisory said that new attack campaigns take advantage of these products’ brand power. The team uncovered the campaigns while analyzing network artifacts, targeting Ukrainian military organizations through spoofed versions of Advanced IP Scanner software.

 

The team uncovered spoofed KeePass and PDF Reader Pro websites in the Ukrainian language. Based on the analysis of the terms of service (TOS) of these websites and the SSL certificates of command-and-control (C2), the team believes that some English-speaking countries are targeted, including the United Kingdom, although Ukraine appears to be the primary target.

 

RomCom followed a straightforward plan to get ready for an attack: stealing the original legitimate HTML code from the vendor to spoof; registering a malicious domain that looks similar to the legitimate one; Trojanizing an application; uploading a malicious bundle to the decoy website; sending targeted phishing emails to the victims; or, in some cases, using additional infector vectors.

 

According to BlackBerry, these techniques indicate a connection between the RomCom and the Cuba ransomware and Industrial Spy, a relatively new ransomware group that emerged in April 2022. A list of RomCom RAT Indicators of Compromise (IoCs) is available in the original text of the BlackBerry advisory.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543