NewRomanic Cyber Army Team

Fecha
20 Jun 2026
Actor
unknown---unmapped-actors
Tipo
Reference
Pais
Unknown
Sector
-
Confianza
medium
65
Prioridad analitica
Media

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

3IOCs
0TTPs
unknown---unmapped-actorsActor
UnknownPais

NewRomanic Cyber Army Team

Que es

NewRomanic Cyber Army Team es un actor APT (Advanced Persistent Threat) asociado al grupo regional Unknown / Unmapped Actors. Este grupo ha sido identificado con alias como Whois Wiper, y se relaciona con dominios y recursos públicos verificados a través de OSINT (Open Source Intelligence). No se han encontrado datos de origen o actividades específicas asociadas al grupo en fuentes oficiales.

Contexto

El grupo NewRomanic Cyber Army Team opera bajo el nombre de Unknown / Unmapped Actors, lo que sugiere una falta de mapeo claro en registros de amenazas. Se han identificado dos indicadores de compromiso (IOCs) verificados a través de fuentes OSINT: el dominio www.mcafee.com y un archivo PDF público wp-dissecting-operation-troy.pdf. Estos elementos son parte de una investigación activa sobre actividades maliciosas, aunque no se han confirmado detalles técnicos o objetivos específicos.

Analisis

Indicadores de Compromiso (IOCs) identificados:

Tipo Valor Contexto
Domain www.mcafee.com Recurso verificado a través de OSINT (fuentes públicas)
File wp-dissecting-operation-troy.pdf Documento descargable asociado a una operación de investigación

Los IOCs proporcionados no muestran evidencia directa de actividades maliciosas, pero su presencia sugiere un interés en recursos técnicos y documentación relacionada con amenazas. No se han encontrado correlaciones entre estos elementos y otras fuentes de inteligencia.

Conclusion

El grupo NewRomanic Cyber Army Team representa una amenaza potencial asociada a actividades maliciosas no completamente mapeadas. Aunque no hay datos verificables sobre su operación, los IOCs identificados (dominios y documentos públicos) indican un interés en recursos técnicos de seguridad. Se recomienda monitorear fuentes OSINT para detectar futuras actividades relacionadas con este grupo.

Diamond Model

Adversary
unknown---unmapped-actors
Ver perfil →
Victim
NewRomanic Cyber Army Team
www.mcafee.com
Capability
Reference
Infrastructure
www.mcafee.com

Relations

Mapa de nodos relacionados por IOCs compartidos, actor, enlaces IntelTracker/OSINT, campanas y victimas observadas. Haz click en un nodo para abrir el post, filtro o fuente.

10 enlaces
Nodo actual
NewRomanic Cyber Army Team
unknown---unmapped-actors
Victima
Persistency: tipically launching ransomware after operation to destroy evidences,Threat Recon.nshc.net alias=SectorA01,http://www.mcafee.com/us/resources/white-papers/wp-dissecting-operation-troy.pdf,http://researchcenter.paloaltonetworks.com/2015/11/tdrop2-attacks-suggest-dark-seoul-attackers-return/,https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Report.pdf,https://www.alienvault.com/open-threat-exchange/blog/operation-blockbuster-unveils-the-actors-behind-the-sony-attacks,https://www.us-cert.gov/ncas/alerts/TA17-164A,http://www.fsec.or.kr/common/proc/fsec/bbs/21/fileDownLoad/1235.do,https://researchcenter.paloaltonetworks.com/2017/08/unit42-blockbuster-saga-continues/,https://www.crowdstrike.com/blog/unprecedented-announcement-fbi-implicates-north-korea-destructive-attacks/,https://www.us-cert.gov/ncas/alerts/TA17-318A,https://www.us-cert.gov/ncas/alerts/TA17-318B,https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf,https://securingtomorrow.mcafee.com/mcafee-labs/lazarus-resurfaces-targets-global-banks-bitcoin-users/,https://www.darkreading.com/vulnerabilities---threats/lazarus-group-fancy-bear-most-active-threat-groups-in-2017/d/d-id/1330954?print=yes,https://www.us-cert.gov/HIDDEN-COBRA-North-Korean-Malicious-Cyber-Activity, https://securelist.com/operation-applejeus/87553/,https://blogs.microsoft.com/on-the-issues/2017/12/19/microsoft-facebook-disrupt-zinc-malware-attack-protect-customers-internet-ongoing-cyberthreats/,https://www.secureworks.com/about/press/media-alert-secureworks-discovers-north-korean-cyber-threat-group-lazarus-spearphishing,https://threatrecon.nshc.net/2019/01/23/sectora01-custom-proxy-utility-tool-analysis/,https://objective-see.com/blog/blog_0x49.html,https://www.sentinelone.com/blog/lazarus-apt-targets-mac-users-poisoned-word-document/,https://blog.alyac.co.kr/2827,https://www.sentinelone.com/blog/four-distinct-families-of-lazarus-malware-target-apples-macos-platform/,https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/,https://www.welivesecurity.com/2020/06/17/operation-interception-aerospace-military-companies-cyberspies/,https://www.mcafee.com/blogs/other-blogs/mcafee-labs/operation-north-star-a-job-offer-thats-too-good-to-be-true/,https://www.clearskysec.com/operation-dream-job/,https://blogs.jpcert.or.jp/en/2020/08/Lazarus-malware.html,https://medium.com/s2wlab/analysis-of-threatneedle-c-c-communication-feat-google-tag-warning-to-researchers-782aa51cf74,https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/,https://www.microsoft.com/security/blog/2021/01/28/zinc-attacks-against-security-researchers/,https://www.hvs-consulting.de/lazarus-report/,https://blog.chainalysis.com/reports/lazarus-group-kucoin-exchange-hack,https://securelist.com/lazarus-threatneedle/100803/,https://www.clearskysec.com/wp-content/uploads/2021/05/CryptoCore-Lazarus-Clearsky.pdf,https://blog.alyac.co.kr/3814,https://www.cisa.gov/uscert/ncas/alerts/aa22-108a,https://www.sentinelone.com/blog/lazarus-operation-interception-targets-macos-users-dreaming-of-jobs-in-crypto/,https://www.microsoft.com/security/blog/2022/09/29/zinc-weaponizing-open-source-software/,https://securelist.com/dtrack-targeting-europe-latin-america/107798/,https://www.volexity.com/blog/2022/12/01/buyer-beware-fake-cryptocurrency-applications-serving-as-front-for-applejeus-malware/,https://www.microsoft.com/en-us/security/blog/2022/12/06/dev-0139-launches-targeted-attacks-against-the-cryptocurrency-industry/,https://labs.withsecure.com/content/dam/labs/docs/WithSecure-Lazarus-No-Pineapple-Threat-Intelligence-Report-2023.pdf,https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/,https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/,https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/
Valor www.mcafee.com
IOC compartido
Victima
JCPenney
Valor
IOC compartido
Victima
APT2
Valor
IOC compartido
Victima
APT16
Valor
IOC compartido
Victima
APT6
Valor
IOC compartido
Victima
Lotus Blossom
Valor
IOC compartido
Victima
APT26
Valor
IOC compartido
Victima
such as WCE
Valor
IOC compartido

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
Tipo Valor Contexto VT OffSec SOCRadar
Domain www.mcafee.com Recurso verificado a través de OSINT (fuentes públicas) VT OffSec SOCRadar
File wp-dissecting-operation-troy.pdf Artefacto observado VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor unknown---unmapped-actors en el blog → Ver unknown---unmapped-actors en IntelTracker → Buscar unknown---unmapped-actors en APTTrail → Repositorio APTTrail → Buscar en Google News → Analizar en VirusTotal → Buscar en Shodan → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes