Excel-lerating cyberattacks.
ID: 17482ad1-0a79-5dbc-aa8b-0e457dcc5107
STIX ID: report--17482ad1-0a79-5dbc-aa8b-0e457dcc5107
Feed Name: The CyberWire
SentinelLabs reports a Ghostwriter campaign attributed to Belarusian government-linked espionage that actively targets Ukrainian government and military organizations and Belarusian opposition activists using weaponized Excel documents. The researchers observed new malware variants and obfuscated VBA macros that load DLL payloads, with payload delivery apparently tailored by target location and system profile; the operation was prepared in mid-2024 and active by late 2024, representing an escalation that blends disinformation and cyber intrusion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
