Also known as: tracked as
TA829 is a Russia-aligned threat actor that employs the RomCom RAT for intelligence-gathering and financially motivated cyberattacks, exploiting zero-day vulnerabilities in Mozilla Firefox and Microsoft Windows. The group utilizes REM Proxy services hosted on compromised MikroTik routers to relay traffic and disguise its origin. In their operations, victims targeted by TA829 receive a strain known as SlipScreen, while their infrastructure and tactics show significant similarities to those of UNK_GreenSec. TA829's hybrid approach combines espionage with financial fraud, making it a notable player in the cyber threat landscape.
Executive Summary
TA829 is a Russia-aligned threat actor known for leveraging the RomCom RAT, REM Proxy services, and zero-day vulnerabilities targeting critical sectors. Their operations combine espionage with financial fraud, making them a significant risk to organizations in government, energy, healthcare, and critical infrastructure.
Goals & Targeting
TA829 appears motivated by both intelligence gathering, likely for espionage purposes, and financial gain through cyberattacks. Their targeting of government, critical infrastructure, energy, and healthcare sectors indicates a focus on high-value assets that offer significant data and potential monetization opportunities.
Enhanced Description
TA829 operates with sophistication, employing advanced techniques such as zero-day exploits on Mozilla Firefox and Microsoft Windows to compromise systems. The group uses REM Proxy services hosted on compromised MikroTik routers for traffic relay and operational disguise, a tactic reminiscent of UNK_GreenSec. Targeted sectors include government, critical infrastructure, energy, and healthcare, suggesting a focus on high-value data and strategic disruption. TA829's dual-use capabilities—espionage and financial fraud—pose a unique threat to organizations, deploying custom malware (RomCom RAT) and leveraging advanced tools and techniques.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TA829's campaigns typically involve targeted attacks against high-value sectors, with evidence of long-term operational persistence. Their use of REM Proxy infrastructure and MikroTik routers suggests a patient, well-resourced threat group capable of maintaining persistent access to victim networks. Key campaign attributes include the deployment of zero-day exploits, stealthy propagation via C2 channels, and data exfiltration through compromised systems.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the available data. While TA829's operational tradecraft is well-documented, gaps exist regarding specific campaign details, exact timelines of activity (first seen/last seen), and confirmed impact assessments linked to their operations.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
89
IOCs
0
Observed Data
0
Tactics