logo

Ghostwriter group resumes attacks on Ukrainian Government targets

ID: cddf396c-600e-5af8-abb0-eea2be2c6c08

STIX ID: report--cddf396c-600e-5af8-abb0-eea2be2c6c08

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Pierluigi Paganini

...
...

ESET discovered a FrostyNeighbor/Ghostwriter campaign since March 2026 targeting Ukrainian government organizations via spear-phishing PDFs that geofence victims (only delivering malicious RAR/JS to Ukrainian IPs). The JS PicassoLoader profiles hosts and checks in periodically; operators manually decide whether to deploy a Cobalt Strike beacon. The operation uses process masquerading, registry persistence, Cloudflare-backed C2, and decoy documents to evade automated analysis, with IOCs published by ESET and recommendations for targeted sectors to review detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.