Ghostwriter | New Campaign Targets Ukrainian Government and Belarusian Opposition
ID: 45b6cccc-0f85-5913-a991-4a435af4424b
STIX ID: report--45b6cccc-0f85-5913-a991-4a435af4424b
Threat Score
SentinelLABS outlines an active Ghostwriter (UNC1151/UAC-0057) campaign targeting Belarusian opposition and Ukrainian government/military using weaponized XLS documents with obfuscated VBA macros that drop ConfuserEx-protected .NET downloaders (PicassoLoader-like) and staged DLLs; attackers use regsvr32/rundll32 persistence and fetch payloads from several .shop C2 domains, and the report includes technical analysis, infection-chain diagrams, and IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
