logo

GhostShell Malware Targets Ukraine's UAV and Defense Supply Chain

ID: 79964421-e449-52dc-a608-954215a412da

STIX ID: report--79964421-e449-52dc-a608-954215a412da

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-06-25

Date Updated: 2026-06-26

...
...

The GhostShell campaign is actively targeting Ukraine’s UAV operations and defense supply chain using socially engineered decoy documents to deliver a multi-stage intrusion chain (VBS scripts, Telegram-based loaders) and custom malware (122.exe), alongside mTLS-authenticated implants; activity is linked to Vidar infostealer infrastructure. Security teams are advised to implement strict mTLS certificate validation, isolate affected systems for memory forensics, and review network logs and domain indicators for signs of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.