logo

UAC-0057 Attack Detection: OYSTERFRESH, OYSTERSHUCK, and OYSTERBLUES Fuel Phishing Campaigns Against Ukrainian State Organizations

ID: 62c14ba0-8e88-58a5-8402-a7af09abb348

STIX ID: report--62c14ba0-8e88-58a5-8402-a7af09abb348

Feed Name: SOC Prime Blog

Threat Score
88/100

Date Published: 2026-05-25

Date Updated: 2026-05-25

Author: SOC Prime Team

...
...

CERT-UA-linked reporting describes a spring 2026 phishing campaign by UAC-0057 (Ghostwriter/UNC1151) that uses Prometheus-themed lures and compromised real accounts to distribute a staged JavaScript toolset (OYSTERFRESH, OYSTERSHUCK, OYSTERBLUES). The chain begins with a PDF link to a ZIP containing a JavaScript downloader that stores an obfuscated payload in the Windows Registry, decodes it, fingerprints hosts, and communicates with Cloudflare-masked C2 infrastructure—with follow-on delivery of Cobalt Strike—while the report maps observed TTPs to MITRE ATT&CK for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.