FrostyNeighbor Targets Ukrainian Government with Evolving Cyber Tactics
ID: 04e5baea-203b-5983-a365-172af58f102f
STIX ID: report--04e5baea-203b-5983-a365-172af58f102f
Feed Name: ThreatCluster
Threat Score
FrostyNeighbor, a Belarus-aligned APT active since at least 2016, has intensified spearphishing operations against Ukrainian government organizations using malicious PDFs that lead to a JavaScript variant of the PicassoLoader downloader to deploy Cobalt Strike; campaigns impersonate Ukrtelecom and have leveraged CVE-2023-38831, with ESET telemetry corroborating the activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
