New RomCom Backdoor Targets Female Political Leaders

Oct. 16, 2023
New RomCom Backdoor Targets Female Political Leaders

Japanese cybersecurity provider Trend Micro has uncovered a new malicious campaign targeting female political leaders and attendees of the Women Political Leaders (WPL) Summit held in Brussels in June 2023.

The treat actors, Void Rabisu, started deploying a new version of its RomCom backdoor – which Trend Micro tracks as RomCom 4.0 and Microsoft as Peapod – in early August 2023, Trend Micro reported in a malware analysis published on October 13.

The backdoor payload was hidden in a malicious copy of the official website of the WPL Summit, which aims to improve gender equality in politics.

“While the ‘Videos & photos’ link of the legitimate domain redirects visitors to a Google Drive folder containing photographs from the event, the wplsummit[.]com fake website directed visitors to a OneDrive folder containing two compressed files and an executable called Unpublished Pictures 1-20230802T122531-002-sfx.exe. The latter file appears to be a piece of malware,” reads the Trend Micro report.

Tags:

No tags.

JikGuard.com, a high-tech security service provider focusing on game protection and anti-cheat, is committed to helping game companies solve the problem of cheats and hacks, and providing deeply integrated encryption protection solutions for games.

Explore Features>>