logo

Tracking Adversaries: Ghostwriter APT Infrastructure

ID: 1706e530-2c37-5073-abab-cf6f87cc9eeb

STIX ID: report--1706e530-2c37-5073-abab-cf6f87cc9eeb

Feed Name: BushidoToken Blog

Threat Score
85/100

Date Published: 2025-01-19

Date Updated: 2026-05-08

...
...

This report explains how CTI analysts pivot on adversary infrastructure to expand visibility into a Ghostwriter (UNC1151) campaign that used malicious XLS macros to drop Cobalt Strike beacons. It documents overlapping IOCs (multiple .shop domains sharing registrar/name servers/robots.txt), shows how additional domains and related malware samples were discovered via VirusTotal and registration-pattern searches (listing ~24 likely malicious domains), and highlights lessons on leveraging infrastructure attributes for attribution and discovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.