ATT&CKSoftwareROAMINGHOUSE

ROAMINGHOUSE

S9026

Malware.View on attack.mitre.org

About this malware

ROAMINGHOUSE is a dropper malware used by MirrorFace to extract and execute embedded payloads including UPPERCUT components.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

ROAMINGHOUSE can embed a ZIP file containing UPPERCUT components into three base64 encoded parts.

T1047
Windows Management Instrumentation

ROAMINGHOUSE can use WMI to launch a legitimate executable later used to enable DLL sideloading.

T1137.001
Office Template Macros

ROAMINGHOUSE has been loaded as a Word Template file when victims opened a decoy document placed in `%APPDATA%\Microsoft\Templates` alongside a ROAMINGHOUSE macro.

T1140
Deobfuscate/Decode Files or Information

ROAMINGHOUSE can decode and drop a malicious ZIP file prior to execution.

T1204.001
Malicious Link

ROAMINGHOUSE has been executed through luring victims into clicking links to download malicious ZIP files.

T1204.002
Malicious File

During Operation AkaiRyū, MirrorFace used malicious files to drop ROAMINGHOUSE.

T1480
Execution Guardrails

ROAMINGHOUSE can change its execution method to create a batch file in the startup folder that executes a legitimate executable if a McAfee product is detected.

T1497.002
User Activity Based Checks

ROAMINGHOUSE can check for specific mouse movements and user activity before initiating malicious activity.

T1518.001
Security Software Discovery

ROAMINGHOUSE can identify McAfee applications on compromised hosts and change its execution method if one is detected.

T1566.002
Spearphishing Link

ROAMINGHOUSE has been distributed through phishing emails containing malicious OneDrive links.

T1574.001
DLL

ROAMINGHOUSE can use a legitimate EXE to sideload a malicious DLL named JSFC.dll. ROAMINGHOUSE has also used ScnCfg32.exe to sideload vsodscpl.dll to enable UPPERCUT execution.

Groups that use it1

Campaigns1

References1

  1. Trend Micro Earth Kasha Updates APR 2025 Open source
    Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.