FrostyNeighbor: Fresh mischief and digital shenanigans
ID: d14ab335-d68a-5260-b6ba-aa49caa91892
STIX ID: report--d14ab335-d68a-5260-b6ba-aa49caa91892
Feed Name: WeLiveSecurity (ESET Research)
Threat Score
FrostyNeighbor (aka Ghostwriter/UNC1151) conducted March 2026 spearphishing campaigns against Ukrainian governmental targets using lure PDFs that fetch a JavaScript dropper and a JavaScript PicassoLoader downloader which fingerprints victims and, after server-side (and likely manual) validation, delivers a Cobalt Strike beacon; the report includes technical analysis of the compromise chain, file and network IoCs, and mapped ATT&CK techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
