Port 22

RomCom RAT Targeting NATO and Ukraine Support Groups

The threat actors behind the RomCom RAT have been suspected of phishing attacks targeting theupcoming NATO Summitin Vilnius as well as an identified organization supporting Ukraine abroad. The findings come from the BlackBerry Threat Research and Intelligence team, whichfoundtwo malicious documents submitted from a Hungarian IP address on July 4, 2023. RomCom, also tracked under the names