GhostShell Malware Targets Ukraine's UAV and Defense Supply Chain
ID: 79964421-e449-52dc-a608-954215a412da
STIX ID: report--79964421-e449-52dc-a608-954215a412da
Feed Name: ThreatCluster
The GhostShell campaign is actively targeting Ukraine’s UAV operations and defense supply chain using socially engineered decoy documents to deliver a multi-stage intrusion chain (VBS scripts, Telegram-based loaders) and custom malware (122.exe), alongside mTLS-authenticated implants; activity is linked to Vidar infostealer infrastructure. Security teams are advised to implement strict mTLS certificate validation, isolate affected systems for memory forensics, and review network logs and domain indicators for signs of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
