logo

'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine

ID: 39fa64af-ed61-5392-999b-d84c3e4d4f99

STIX ID: report--39fa64af-ed61-5392-999b-d84c3e4d4f99

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Elizabeth Montalbano

...
...

ESET and Dark Reading detail a targeted FrostyNeighbor (Ghostwriter/UNC1151) espionage campaign since March that uses spear-phishing PDFs pointing to attacker infrastructure; a JavaScript PicassoLoader fingerprints victims and, for selected Ukrainian/Polish targets, stages a JavaScript dropper that deploys Cobalt Strike. The actors perform server-side victim validation and manual selection to avoid non-targets; the report highlights evolving TTPs, IoCs, and mitigation guidance for government and military organizations in Eastern Europe.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.