TA829 Hackers Deploy New TTPs and Upgraded RomCom Backdoor to Bypass Detection

The threat landscape has seen a notable escalation in sophistication as the TA829 threat actor, known for blending espionage and financially motivated cybercrime, has returned with enhanced tactics, techniques, and procedures (TTPs) and an upgraded version of its RomCom-based backdoor.

Recent activity tracked by Proofpoint reveals TA829’s continued reliance on a custom tool suite, now featuring more advanced evasion and delivery mechanisms, and a convergence with another cybercriminal cluster, “UNK_GreenSec,” that has introduced the new TransferLoader malware.

TA829: Blurring Espionage and Cybercrime

TA829 operates at the intersection of cybercrime and espionage, leveraging services from the criminal underground and regularly updating its toolset, which is built upon the legacy RomCom backdoor.

RomCom Backdoor
Illustration highlighting delivery and installation for the UNK_GreenSec and TA829. 

Following the 2022 invasion of Ukraine, TA829 expanded its operations to include targeted espionage campaigns aligned with Russian state interests, while maintaining its financially driven attacks.

This duality is reflected in the group’s automated and scalable processes: frequent updates to packers and loaders, varied sending infrastructure, and extensive redirection chains that complicate detection and attribution.

Phishing remains TA829’s primary vector, with campaigns deploying variants of the SingleCamper (aka SnipBot, an evolved RomCom backdoor) and DustyHammock malware.

These campaigns typically use plaintext emails sent from compromised MikroTik routers via freemail providers, often spoofing OneDrive or Google Drive links to initiate infection.

The infection chain is notable for its use of the SlipScreen loader, which is invalidly signed, masquerades as a PDF reader, and checks the Windows Registry for recent documents to evade sandbox analysis.

After initial checks, SlipScreen decrypts and loads shellcode, establishing communication with the command-and-control (C2) infrastructure.

TA829’s infection chain can deliver updated RustyClaw or MeltingClaw loaders, both capable of deploying DustyHammock or SingleCamper backdoors.

These backdoors share a unified beacon structure and can be administered from the same management panel, supporting both espionage and cybercriminal objectives.

Recent campaigns have also introduced the ShadyHammock tool suite, which enhances payload encryption using victim-specific host information and increases operational security.

TransferLoader and UNK_GreenSec

During a lull in TA829 activity in early 2025, Proofpoint identified a parallel set of campaigns attributed to UNK_GreenSec, a cluster that shares significant infrastructure and delivery TTPs with TA829.

RomCom Backdoor
Email lure used by TA829 in February 2025. 

These campaigns, which targeted North America with thousands of phishing emails themed around job applications, introduced TransferLoader a new loader designed for stealth and modular payload delivery.

TransferLoader employs advanced evasion techniques, including filename verification, custom encryption and encoding algorithms, and dynamic API resolution from 64-bit DLLs.

The malware only executes if specific strings remain in the filename, thwarting many automated analysis tools.

TransferLoader campaigns utilize similar delivery infrastructure as TA829, including REM Proxy services on compromised MikroTik routers and Rebrandly redirectors.

However, UNK_GreenSec has demonstrated more mature infrastructure protection, incorporating Cloudflare filtering and dynamic, server-side checks to block researchers and automated scanners.

The final payloads are often delivered via IPFS webshares, and infections have resulted in the deployment of Metasploit and Morpheus ransomware, an updated HellCat variant.

The overlap in TTPs, infrastructure, and malware between TA829 and UNK_GreenSec complicates attribution.

Hypotheses range from both clusters sourcing infrastructure from the same underground providers, to temporary service sharing, or even the possibility that TransferLoader represents a new malware family under development by TA829.

The convergence of cybercrime and espionage activities, as exemplified by TA829, underscores the increasing difficulty in distinguishing between financially motivated and state-aligned threat actors in today’s threat landscape.

Indicators of Compromise (IOCs)

IndicatorTypeContextFirst Seen
1drv[.]siteDomainTA829 first stage domainOct 2024
1drv[.]zoneDomainTA829 first stage domainOct 2024
1drvms[.]spaceDomainTA829 first stage domainOct 2024
1drw[.]liveDomainTA829 first stage domainFeb 2025
1share[.]limitedDomainTA829 first stage domainFeb 2025
file-cloud[.]companyDomainTA829 first stage domainFeb 2025
mspdf[.]liveDomainTA829 first stage domainFeb 2025
onedr[.]expertDomainTA829 first stage domainFeb 2025
onefile[.]socialDomainTA829 first stage domainFeb 2025
pdf-share[.]pubDomainTA829 first stage domainFeb 2025
share-doc[.]liveDomainTA829 first stage domainFeb 2025
1drv-storage[.]pubDomainTA829 first stage domainFeb 2025
1drv365[.]liveDomainTA829 first stage domainFeb 2025

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories