logo

Ghostwriter Cyber-Attack Targets Ukrainian, Belarusian Opposition

ID: f95b52e7-eaf4-53d7-878c-8d3af4b38ded

STIX ID: report--f95b52e7-eaf4-53d7-878c-8d3af4b38ded

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2025-02-25

Date Updated: 2026-04-22

...
...

SentinelLABS uncovered a Ghostwriter APT campaign delivering multi-stage malware via weaponized Excel spreadsheets with obfuscated VBA macros (writing a disguised DLL, executing it via regsvr32, and loading .NET assemblies) that targets Ukrainian government entities and Belarusian opposition figures; the group uses PicassoLoader, domain spoofing, PE header modification, and other obfuscation techniques, and organizations in the region are advised to disable macros, use email filtering and EDR, and monitor network activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.