Hackers Exploit Scheduled Tasks for Persistence in FrostyNeighbor Attacks
ID: c7ac50c0-63ca-5bd5-8093-191a0d94a9c6
STIX ID: report--c7ac50c0-63ca-5bd5-8093-191a0d94a9c6
Feed Name: GBHackers
A cyber‑espionage campaign attributed to FrostyNeighbor (Ghostwriter/UNC1151/TA445) has intensified against Ukrainian government organizations using spear‑phishing PDFs that perform server‑side validation to serve benign decoys outside Ukraine and malicious RAR/JavaScript payloads to targets; the actor deploys a JavaScript PicassoLoader downloader which performs reconnaissance and, for high‑value victims, installs a Cobalt Strike beacon. The campaign shows increased stealth and persistence via abuse of Windows scheduled task XML templates, renamed legitimate binaries and registry/shortcut persistence, indicating a highly adaptive, state‑aligned APT targeting government and defense sectors in Eastern Europe.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
