Also known as: Storm-0978, Tropical Scorpius, APT28, Smoke Sandstorm, tracked as, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, VOLTZITE, for follow-on operations, Tech Sectors, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, APT44, Seashell Blizzard, BlackEnergy, PHANTOM, September 2025, Void Rabisu, operated by TA569, RomCom, the Bulldog backdoor, defense-industry organizations, TA455, Yellow Liderc, Tortoiseshell, aviation, IMPERIAL KITTEN, Imperial Kitten, TA456, DUSTYCAVE, Crimson Sandstorm, Cuboid Sandstorm, CURIUM, Agrius, APT34, Royal Ransomware, Blue Echidna, UNC2596, GOFFEE, Fluffy Wolf, LuoYu, CASCADE PANDA, Qilin, file transfer tools, UNC1549, APT33, Fancy Bear, Samurai Panda, PLA Navy, APT4, Wisp Team, APT35, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, IRIDIUM, FROZENBARENTS, UAC-0113, UAC-0082, SANDWORM RELIC, Newscaster Team, Magic Hound, G0059, Phosphorus, Mint Sandstorm, TunnelVision, COBALT MIRAGE, Agent Serpens, RICH ION, BOHRIUM, DEV-0228
SHADOW-VOID-042 is an emergent intrusion set that surfaced in late‑2025 and has been linked to a series of sophisticated spear‑phishing operations. The group targets a broad spectrum of industries—including energy, defense, pharmaceuticals, financial services, telecommunications, manufacturing, and aerospace—across numerous countries such as the United States, Russia, Ukraine, China, Iran, India, and Saudi Arabia. Campaign emails frequently mimic official Trend Micro communications or present themselves as HR complaints or research surveys to lure recipients into executing malicious attachments or visiting compromised web pages. The attacker employs an intricate multi‑stage loader architecture. Initially a shellcode stub embedded in JavaScript is delivered via phishing or compromised vendor updates; the code contacts the adversary’s command‑and‑control (C2) on TCP port 1026 with an opaque four‑byte magic header (0x36694201). After establishing contact, it downloads an encrypted Stage 2 binary—SystemProcessHost.exe—writes it to disk, and schedules a scheduled task named "DavaniGulyashaSdeshka" for persistence. Subsequent stages retrieve further payloads through an API hashing scheme with retries on hardcoded C2 endpoints. In addition to stealthy delivery, SHADOW-VOID-042 demonstrates destructive intent by deploying data‑wiping tools ZeroLot and Sting via Group Policy manipulation and scheduled tasks against Ukrainian entities. The adversary also leverages the Chrome vulnerability CVE‑2018‑6065 through injected JavaScript that redirects victims through a Cloudflare‑impersonating chain, exemplifying its ability to integrate web‑based exploitation with desktop payloads. Operationally, the group shares infrastructure and TTP similarities with the Void Rabisu (ROMCOM) operatives but remains distinct, focusing on non‑Ukraine sectors and lacking confirmed ROMCOM-specific attacks. Their tools feature Netlink kernel sockets for stealth, payload polymorphism, credential theft from "/etc/passwd"/"/etc/shadow", and UDP‑based distributed denial‑of‑service capabilities. Overall, SHADOW-VOID-042 presents a versatile threat that blends social engineering, web exploitation, lateral movement techniques, and destructive malware to achieve both financial gains and infrastructure sabotage.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
SHADOW-VOID-042 is a financially motivated intrusion set active from October to November 2025 that conducts highly tailored spear‑phishing using Trend Micro brand lures, exploiting a Chrome CVE and Windows Group Policy for deployment. The campaign uses multi‑stage loaders with custom C2 over TCP ports 1026/6969, and includes destructive wiper malware ZeroLot/Sting targeting critical infrastructure in Ukraine and beyond.
Goals & Targeting
The strategic objective of SHADOW‑VOID‑042 appears to be dual‑pronged: short‑term financial gain through credential theft and phishing, coupled with long‑term reputational damage or disruption via targeted wipers against critical infrastructure. By focusing on high‑value sectors such as energy, defense, and pharmaceuticals, the actor seeks to leverage the economic impact of downtime while simultaneously signaling capability and intent. The targeting profile reveals a methodical selection of victims based on perceived value and susceptibility rather than geographical bias, although the majority of recent activity points towards Ukrainian infrastructure. The attacker’s use of brand‑spoofed malware and zero‑day browser exploits indicates an emphasis on maximizing compromise likelihood while minimizing user awareness.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
SHADOW‑VOID‑042’s campaigns have a clear operational tempo: rapid deployment of spear‑phishing emails in late‑2025, followed by immediate exploitation of known browser vulnerabilities (Chrome CVE‑2018‑6065) and Windows Group Policy weaknesses. Victims are often industrial, governmental, or commercial organizations with critical infrastructure holdings. The actor routinely establishes persistence via scheduled tasks, deploys destructive wipers against Ukrainian facilities, and exfiltrates credential material for lateral movement. The group’s overlap with Void Rabisu (ROMCOM) suggests shared infrastructure, though the two maintain separate operational foci. This dual presence hints at a broader, modular threat network capable of evolving tactics, techniques, and procedures across multiple campaigns.
IOC Patterns
Recommended Actions
Suggested Tags
Australian Parliament Hack
Citrix Hack
No observed data linked yet.
25
Techniques
53
Tools
2
Campaigns
40
IOCs
0
Observed Data
12
Tactics