logo

FrostyNeighbor Targets Ukrainian Government with Evolving Cyber Tactics

ID: 04e5baea-203b-5983-a365-172af58f102f

STIX ID: report--04e5baea-203b-5983-a365-172af58f102f

Feed Name: ThreatCluster

Threat Score
77/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

...
...

FrostyNeighbor, a Belarus-aligned APT active since at least 2016, has intensified spearphishing operations against Ukrainian government organizations using malicious PDFs that lead to a JavaScript variant of the PicassoLoader downloader to deploy Cobalt Strike; campaigns impersonate Ukrtelecom and have leveraged CVE-2023-38831, with ESET telemetry corroborating the activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.