Female political leaders and military bigwigs targeted by new cyberattack

Anonymous Hacker
(Image credit: TheDigitalArtist / Pixabay)

Hackers have discovered targeting European Union (EU) military personnel and political leaders working on gender equality with an updated version of the RomCom remote access trojan (RAT) called PEAPOD.

According to cybersecurity researchers at Trend Micro, a hacking collective dubbed Void Rabisu (elsewhere known as UNC2596) created a typosquatted version of the wplsummit website - a site promoting the Women Political Leaders (WPL) Summit that happened in June this year. This malicious website displayed a Microsoft OneDrive folder that hosts an executable named "Unpublished Pictures 1-20230802T122531-002-sfx.exe." 

The file is presented as a photo gallery, and while it does hold some photos from the event (picked up from social media), it also carries PEAPOD.

State-sponsored or not?

PEAPOD itself is a slimmed-down version of the RomCom RAT, featuring 10 commands (RomCom has 42). These commands include executing arbitrary code, grabbing system information, and self-destruction in case of compromise. The researchers believe the attackers cut down on unnecessary bulk to make the RAT stealthier and harder to remove.

While the methodology, the victims, and the attackers' identities, are all known - the motives are still a mystery. The Hacker News reports that Void Rabisu is an “unusual” group as they were observed in both financially motivated attacks and espionage campaigns. 

"Void Rabisu is one of the clearest examples where we see a mix of the typical tactics, techniques, and procedures (TTPs) used by cybercriminal threat actors and TTPs used by nation-state-sponsored threat actors motivated primarily by espionage goals," Trend Micro said.

"While we have no evidence that Void Rabisu is nation-state-sponsored, it's possible that it is one of the financially motivated threat actors from the criminal underground that got pulled into cyberespionage activities due to the extraordinary geopolitical circumstances caused by the war in Ukraine," Trend Micro said.

According to the publication, Void Rabisu’s attacks often feature backdoors that single out Ukraine and countries that support it in its war against Russia.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Russia
Major Russian hacking group shifts focus to US and UK targets
Red padlock open on electric circuits network dark red background
Aviation firms hit by devious new polyglot malware
Mustang Panda
Chinese hackers abuse Microsoft tool to get past antivirus and cause havoc
China
Chinese hackers develop effective new hacking technique to go after business networks
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Google Pixel Watch 3 side dial and button
Google Gemini reportedly spotted on Wear OS – could a rollout be close at hand?
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Toni Collette in Hereditary
Everything leaving Netflix in April 2025 – from the scariest movie ever made to a beloved DreamWorks animation with 99% on Rotten Tomatoes
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think