The threat landscape has seen a notable escalation in sophistication as the TA829 threat actor, known for blending espionage and financially motivated cybercrime, has returned with enhanced tactics, techniques, and procedures (TTPs) and an upgraded version of its RomCom-based backdoor.
Recent activity tracked by Proofpoint reveals TA829’s continued reliance on a custom tool suite, now featuring more advanced evasion and delivery mechanisms, and a convergence with another cybercriminal cluster, “UNK_GreenSec,” that has introduced the new TransferLoader malware.
TA829: Blurring Espionage and Cybercrime
TA829 operates at the intersection of cybercrime and espionage, leveraging services from the criminal underground and regularly updating its toolset, which is built upon the legacy RomCom backdoor.

Following the 2022 invasion of Ukraine, TA829 expanded its operations to include targeted espionage campaigns aligned with Russian state interests, while maintaining its financially driven attacks.
This duality is reflected in the group’s automated and scalable processes: frequent updates to packers and loaders, varied sending infrastructure, and extensive redirection chains that complicate detection and attribution.
Phishing remains TA829’s primary vector, with campaigns deploying variants of the SingleCamper (aka SnipBot, an evolved RomCom backdoor) and DustyHammock malware.
These campaigns typically use plaintext emails sent from compromised MikroTik routers via freemail providers, often spoofing OneDrive or Google Drive links to initiate infection.
The infection chain is notable for its use of the SlipScreen loader, which is invalidly signed, masquerades as a PDF reader, and checks the Windows Registry for recent documents to evade sandbox analysis.
After initial checks, SlipScreen decrypts and loads shellcode, establishing communication with the command-and-control (C2) infrastructure.
TA829’s infection chain can deliver updated RustyClaw or MeltingClaw loaders, both capable of deploying DustyHammock or SingleCamper backdoors.
These backdoors share a unified beacon structure and can be administered from the same management panel, supporting both espionage and cybercriminal objectives.
Recent campaigns have also introduced the ShadyHammock tool suite, which enhances payload encryption using victim-specific host information and increases operational security.
TransferLoader and UNK_GreenSec
During a lull in TA829 activity in early 2025, Proofpoint identified a parallel set of campaigns attributed to UNK_GreenSec, a cluster that shares significant infrastructure and delivery TTPs with TA829.

These campaigns, which targeted North America with thousands of phishing emails themed around job applications, introduced TransferLoader a new loader designed for stealth and modular payload delivery.
TransferLoader employs advanced evasion techniques, including filename verification, custom encryption and encoding algorithms, and dynamic API resolution from 64-bit DLLs.
The malware only executes if specific strings remain in the filename, thwarting many automated analysis tools.
TransferLoader campaigns utilize similar delivery infrastructure as TA829, including REM Proxy services on compromised MikroTik routers and Rebrandly redirectors.
However, UNK_GreenSec has demonstrated more mature infrastructure protection, incorporating Cloudflare filtering and dynamic, server-side checks to block researchers and automated scanners.
The final payloads are often delivered via IPFS webshares, and infections have resulted in the deployment of Metasploit and Morpheus ransomware, an updated HellCat variant.
The overlap in TTPs, infrastructure, and malware between TA829 and UNK_GreenSec complicates attribution.
Hypotheses range from both clusters sourcing infrastructure from the same underground providers, to temporary service sharing, or even the possibility that TransferLoader represents a new malware family under development by TA829.
The convergence of cybercrime and espionage activities, as exemplified by TA829, underscores the increasing difficulty in distinguishing between financially motivated and state-aligned threat actors in today’s threat landscape.
Indicators of Compromise (IOCs)
| Indicator | Type | Context | First Seen |
|---|---|---|---|
| 1drv[.]site | Domain | TA829 first stage domain | Oct 2024 |
| 1drv[.]zone | Domain | TA829 first stage domain | Oct 2024 |
| 1drvms[.]space | Domain | TA829 first stage domain | Oct 2024 |
| 1drw[.]live | Domain | TA829 first stage domain | Feb 2025 |
| 1share[.]limited | Domain | TA829 first stage domain | Feb 2025 |
| file-cloud[.]company | Domain | TA829 first stage domain | Feb 2025 |
| mspdf[.]live | Domain | TA829 first stage domain | Feb 2025 |
| onedr[.]expert | Domain | TA829 first stage domain | Feb 2025 |
| onefile[.]social | Domain | TA829 first stage domain | Feb 2025 |
| pdf-share[.]pub | Domain | TA829 first stage domain | Feb 2025 |
| share-doc[.]live | Domain | TA829 first stage domain | Feb 2025 |
| 1drv-storage[.]pub | Domain | TA829 first stage domain | Feb 2025 |
| 1drv365[.]live | Domain | TA829 first stage domain | Feb 2025 |
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates