logo

Excel-lerating cyberattacks.

ID: 17482ad1-0a79-5dbc-aa8b-0e457dcc5107

STIX ID: report--17482ad1-0a79-5dbc-aa8b-0e457dcc5107

Feed Name: The CyberWire

Threat Score
85/100

Date Published: 2025-03-22

Date Updated: 2026-04-23

...
...

SentinelLabs reports a Ghostwriter campaign attributed to Belarusian government-linked espionage that actively targets Ukrainian government and military organizations and Belarusian opposition activists using weaponized Excel documents. The researchers observed new malware variants and obfuscated VBA macros that load DLL payloads, with payload delivery apparently tailored by target location and system profile; the operation was prepared in mid-2024 and active by late 2024, representing an escalation that blends disinformation and cyber intrusion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.