Alias Description | Votes |
---|---|
Tropical Scorpius is a possible alias for Void Rabisu. Tropical Scorpius, also known as RomCom, Storm-0978, and UNC2596, is a threat actor group that has been active since at least late 2020. This Russian-based cybercrime group is associated with Cuba ransomware and the RomCom backdoor, and it has exploited various techniques such as Magic bytes, Proces | 3 |
Unc2596 is a possible alias for Void Rabisu. UNC2596, also known as RomCom, Storm-0978, Tropical Scorpius, and Void Rabisu, is a Russian-based cybercrime group that has executed a series of attacks across Europe and North America. The threat actor has exploited two zero-day vulnerabilities in Firefox and Tor Browser in its recent operations. R | 3 |
Alias Description | Association Type | Votes |
---|---|---|
The Romcom Backdoor Malware is associated with Void Rabisu. The RomCom backdoor is a malicious software (malware) primarily utilized by the threat actor Void Rabisu, which has been linked to the pro-Russian APT group known as Storm-0978 or the RomCom Group. The malware is typically spread through deceptive websites that redirect potential victims to a server | has used | 3 |
The RomCom Malware is associated with Void Rabisu. RomCom, a malicious software, has been identified as a significant cyber threat. Reports from third-party and open-source intelligence since spring 2022 have indicated a connection between RomCom Remote Access Trojan (RAT) actors, Cuba ransomware actors, and Industrial Spy ransomware actors. The mal | has used | 3 |
The Peapod Malware is associated with Void Rabisu. Peapod is a sophisticated form of malware that has evolved from the RomCom 3.0 backdoor. The cybercriminal group Void Rabisu appears to have transitioned from using RomCom 3.0 to Peapod, which exhibits several architectural differences compared to its predecessor. This new strain, also referred to a | has used | 3 |
The Cuba Ransomware Malware is associated with Void Rabisu. The Cuba ransomware is a malicious software that first appeared on cybersecurity radars in late 2020 under the name "Tropical Scorpius." It is designed to exploit and damage computer systems, often infiltrating through suspicious downloads, emails, or websites without the user's knowledge. Once insi | has used | 2 |
Alias Description | Association Type | Votes |
---|---|---|
The CVE-2023-36884 Vulnerability is associated with Void Rabisu. CVE-2023-36884 is a significant software vulnerability that affects Microsoft Windows, Server, Office, and Outlook. This flaw in the design or implementation of these software platforms allows for remote code execution (RCE), which has been exploited by cybercriminals and potentially state-sponsored | Unspecified | 3 |
Preview | Source Link | CreatedAt | Title |
---|---|---|---|
CERT-EU | a year ago | ||
CERT-EU | a year ago | ||
CERT-EU | a year ago | ||
BankInfoSecurity | a year ago | ||
CERT-EU | a year ago | ||
CERT-EU | a year ago | ||
CERT-EU | a year ago | ||
CERT-EU | a year ago | ||
CERT-EU | a year ago | ||
DARKReading | a year ago | ||
InfoSecurity-magazine | a year ago | ||
CERT-EU | a year ago | ||
CERT-EU | a year ago | ||
CERT-EU | a year ago | ||
CERT-EU | a year ago | ||
CERT-EU | a year ago | ||
Trend Micro | a year ago | ||
CERT-EU | a year ago | ||
CERT-EU | a year ago | ||
CERT-EU | a year ago |