Cybersecurity researchers have identified a Russian-speaking cyber espionage group called Nebulous Mantis that has been deploying the sophisticated RomCom RAT (Remote Access Trojan) since mid-2022. According to Swiss cybersecurity firm PRODAFT, this malware “employs advanced evasion techniques, including living-off-the-land tactics and encrypted command and control communications, while continuously evolving its infrastructure.”
The threat actor, also known by aliases CIGAR, Cuba, Storm-0978, Tropical Scorpius, UNC2596, and Void Rabisu, primarily targets critical infrastructure, government agencies, political leaders, and NATO-related defense organizations.
## Attack Methodology
Nebulous Mantis typically initiates attacks through spear-phishing emails containing weaponized document links that deliver RomCom RAT. Their infrastructure relies on bulletproof hosting services like LuxHost and Aeza, managed by a threat actor identified as LARVA-290, who has been active since at least mid-2019.
The multi-stage attack begins with a first-stage RomCom DLL that connects to command-and-control servers to download additional payloads using the InterPlanetary File System (IPFS). The final-stage C++ malware establishes persistent communication channels to execute commands and deploy modules capable of stealing web browser data.
## Advanced Capabilities
RomCom’s sophisticated toolkit includes:
– Windows Registry manipulation for persistence via COM hijacking
– Credential harvesting
– System reconnaissance
– Active Directory enumeration
– Lateral movement capabilities
– Collection of sensitive data including files, credentials, and Microsoft Outlook backups
The malware also gathers system time zone information to align attack activities with victim working hours and evade time-based security controls.
## Operational Structure
The threat actors manage RomCom variants and victims through a dedicated C2 panel that enables remote execution of over 40 different commands for data collection. PRODAFT notes that “Nebulous Mantis exhibits operational discipline in minimizing their footprint, carefully balancing aggressive intelligence collection with stealth requirements,” suggesting either state sponsorship or a well-resourced professional cybercriminal organization.
This revelation follows PRODAFT’s recent exposure of another group, Ruthless Mantis (PTI-288), which specializes in ransomware double extortion through collaboration with affiliate programs like Ragnar Locker and INC Ransom.
