logo

FrostyNeighbor: Fresh mischief and digital shenanigans

ID: d14ab335-d68a-5260-b6ba-aa49caa91892

STIX ID: report--d14ab335-d68a-5260-b6ba-aa49caa91892

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-05-15

...
...

FrostyNeighbor (aka Ghostwriter/UNC1151) conducted March 2026 spearphishing campaigns against Ukrainian governmental targets using lure PDFs that fetch a JavaScript dropper and a JavaScript PicassoLoader downloader which fingerprints victims and, after server-side (and likely manual) validation, delivers a Cobalt Strike beacon; the report includes technical analysis of the compromise chain, file and network IoCs, and mapped ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.