RomCom Cyber Threat: How the Infamous Group Targets NATO Summit Attendees

The RomCom threat group has once again emerged, launching a new campaign specifically targeting attendees of a NATO Summit in Lithuania. With Ukrainian President Volodymyr Zelensky expected to participate, the campaign aims to explore Ukraine’s potential future with the organization.

Details of the Campaign

In this sophisticated operation, the RomCom group impersonates the Ukrainian World Congress organization, using fake documents, including a lobbying document claiming to support Ukraine. The prime focus of the campaign revolves around individuals who support Ukraine, particularly those attending the NATO Summit in Vilnius.

Method of Attack

RomCom leverages the exploitation of the .RTF file format to establish a connection with command-and-control (C2) infrastructure under their control. While the initial infection vector remains undisclosed, it is highly likely that the group employed spear-phishing techniques and enticed victims to click on a meticulously crafted replica of the Ukrainian World Congress website. To make the malicious domain appear legitimate, cunning typosquatting tactics are employed, utilizing a .info suffix.

Exploitation of Flaws

An additional weapon in RomCom’s arsenal is an execution chain that takes advantage of a vulnerability present in Microsoft’s Support Diagnostic Tool (MSDT), known as Follina (CVE-2022-30190). If RomCom successfully exploits Follina, they gain the ability to execute remote code attacks through malicious .DOCX or .RTF documents.

History of RomCom

RomCom has previously targeted various Ukrainian and pro-Ukraine entities in Eastern Europe and other parts of the world. Recognized by researchers at Trend Micro, the group’s activities have been consistently monitored and studied.

Recommendations for Defense

To protect themselves from RomCom and other advanced persistent threats (APTs), targets should employ security solutions equipped with behavior-monitoring capabilities. Such solutions can effectively detect and counter the tactics employed by threat groups like RomCom. Adopting a proactive approach to defense is vital in safeguarding against sophisticated cyberattacks.

The RomCom threat group’s latest campaign, which specifically targets the NATO Summit in Lithuania, showcases their determination to exploit geopolitical events for their own gain. By impersonating the Ukrainian World Congress and disseminating fake documents, RomCom aims to manipulate attendees’ perspectives on Ukraine’s potential future with NATO. The ever-evolving tactics employed by RomCom highlight the importance of remaining vigilant and implementing proactive measures to defend against advanced persistent threats. As the cybersecurity landscape continues to evolve, it is imperative that organizations and individuals prioritize security measures capable of mitigating the risks posed by such malicious actors.

Explore more

Trend Analysis: Global Ecommerce Logistics Stabilization

The long-anticipated cooling of the global digital commerce furnace has arrived, replacing the frantic, uncoordinated surges of the early decade with a more calculated and resilient operational rhythm. For years, supply chain managers and retail giants operated under a siege mentality, reacting to unprecedented demand spikes with whatever resources were available, regardless of long-term efficiency. As the calendar settles into

How Is AI Reshaping High-Volume Recruitment?

In the high-stakes world of frontline labor, the sheer velocity of incoming applications has transformed from a metric of success into a logistical nightmare that threatens to paralyze traditional HR departments. The traditional “post and pray” method of recruitment is failing under the weight of modern application volumes, where a single frontline opening can attract hundreds of candidates in a

Is AI Replacing the Spreadsheet in European Wealth Management?

The wealth management industry has reached a tipping point where the manual consolidation of client data is no longer just a nuisance—it is a competitive liability. In the current landscape of 2026, the financial sector is witnessing a departure from the “experimental” phase of artificial intelligence, where chat-based pilots often failed to deliver meaningful returns. The recent partnership between Flanks

How Will Flanks and Perplexity Change Wealth Management?

The days of financial advisors drowning in a sea of disconnected Excel spreadsheets and manual data entries are finally being replaced by a more streamlined era of intelligent automation. This evolution, driven by the partnership between Flanks and Perplexity, shifts the advisor from a data processor toward a high-level strategist. By bridging the gap between AI and regulated data, the

Vyas Enhances Microsoft Unified Pricing for Distributors

In the high-stakes environment of global wholesale distribution, the thin line between a profitable quarter and a margin disaster often depends on whether a company can execute its pricing strategy as quickly as the market moves. Even the most sophisticated financial models lose their value if they cannot be translated into active, accurate sales quotes at the point of transaction.