# RomCom

> As of 2026-07-22, RomCom is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning vulnerability, apt. Also known as Storm-0978, UAT-5647, Paper Werewolf, Tropical Scorpius. ATT&CK coverage spans 55 techniques across 13 tactics in 2 of 2 tracked threats. Most-observed techniques: T1140 (Deobfuscate/Decode Files or Information), T1555 (Credentials from Password Stores), T1005 (Data from Local System).

- **Nation:** Russia
- **Tracked threats:** 2
- **Categories:** VULNERABILITY, APT
- **Also known as:** Storm-0978, UAT-5647, Paper Werewolf, Tropical Scorpius, UNC2596, GOFFEE
- **As of:** 2026-07-22

## ATT&CK techniques observed

55 techniques observed across 2 of 2 tracked threats. Tactics: Stealth (formerly Defense Evasion) (13), Command and Control (6), Discovery (6), Collection (5), Execution (5), Persistence (5).

- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 2 tracked threats
- [T1555](https://intel.threadlinqs.com/technique/T1555) Credentials from Password Stores — Credential Access — observed in 2 of 2 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 1 of 2 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 1 of 2 tracked threats
- [T1025](https://intel.threadlinqs.com/technique/T1025) Data from Removable Media — Collection — observed in 1 of 2 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1027.013](https://intel.threadlinqs.com/technique/T1027.013) Encrypted/Encoded File — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1033](https://intel.threadlinqs.com/technique/T1033) System Owner/User Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 1 of 2 tracked threats
- [T1053](https://intel.threadlinqs.com/technique/T1053) Scheduled Task/Job — Persistence — observed in 1 of 2 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 1 of 2 tracked threats
- [T1059.003](https://intel.threadlinqs.com/technique/T1059.003) Windows Command Shell — Execution — observed in 1 of 2 tracked threats
- [T1070](https://intel.threadlinqs.com/technique/T1070) Indicator Removal — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats

## Tracked threats

- [Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) Exploit Patched WinRAR Path-Traversal CVE-2025-8088 (NTFS ADS) Against Ukrainian Organizations](https://intel.threadlinqs.com/threat/TL-2026-0723) — HIGH
- [RomCom & Paper Werewolf Exploiting WinRAR CVE-2025-8088 Zero-Day via ADS Path Traversal](https://intel.threadlinqs.com/threat/TL-2026-0090) — CRITICAL

## Related CVEs

1 CVE referenced by tracked RomCom activity.

- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/RomCom
