EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

10 Things I Hate About Attribution: RomCom vs. TransferLoader

Verified open source
Intelligence with traceable provenance. EudorIA retains technical indicators acquired from supported feeds, with source, date and context. Shareable IOCs are available in the STIX feeds; detection and blocking actions require an assessment of validity, confidence and applicability to the customer's environment. Browse STIX feeds
EudorIA operational summary

What it means

Priority 55/100

MISP EudorIA ha pubblicato l'advisory "10 Things I Hate About Attribution: RomCom vs. TransferLoader". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.

Why it matters

Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.

AudienceITSOCCISO

Text acquired from the source

Evento MISP pubblicato con TLP:CLEAR: 10 Things I Hate About Attribution: RomCom vs. TransferLoader. Report from - [URL rimossa] (1745170857) ### Key takeaways * TA829 conducts a mixture of espionage and cybercriminal operations, which rely on services sourced from the criminal underground, and a regularly updated suite of tools built upon the legacy RomCom backdoor. * While tracking TA829, Proofpoint observed a highly similar email campaign and redirection infrastructure set-up. This similar campaign deployed a new loader and backdoor dubbed TransferLoader, which Proofpoint currently attributes to a separate cybercriminal cluster called “UNK\_GreenSec”, rather than TA829. * This blog will show how analysts explored the differences and overlaps between both sets of activity and leave an open-ended question around the relationship between these two clusters within the larger criminal and espionage ecosystem. ### Overview Most of the time, delineating activities from distinct clusters and separating cybercrime from espionage can be done based on differing tactics, techniques, and procedures (TTPs), tooling, volume/scale, and targeting. However, in the case of TA829 and a cluster Proofpoint dubbed “UNK\_GreenSec”, there is more ambiguity. TA829 is a cybercriminal actor that occasionally also conducts espionage aligned with Russian state interests, while UNK\_GreenSec is an unusual cybercriminal cluster. TA829 overlaps with activity tracked by third-parties as RomCom, Void Rabisu,

Source
MISP EudorIA
Publishing entity
MISP EudorIA
Entity type
Intelligence community
Area
Global
Original language
it · translation not needed
Publication
30/07/2026 02:52
Sharing
TLP:CLEAR
Indicators reported by the source
124
IOCs indexed for lookup
0 values within the retention period
IOCs available in the STIX feed
124Last sharing verification: 2026-09-26T05:00:58.203767+00:00
MISP event
31de44de-304f-48c4-8ca0-38d1da0b8eba
MITRE ATT&CK
Spearphishing Link - T1566.002
Classification
Medium
Group attributed by the source
RomCom
Open the original source