Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware
ID: 77eceb20-cccf-5fd9-a46d-e4d128e406c4
STIX ID: report--77eceb20-cccf-5fd9-a46d-e4d128e406c4
Feed Name: The Hacker News
CERT-UA attributes a spring-2026 phishing campaign targeting Ukrainian government entities to the Belarus-aligned APT Ghostwriter (UAC-0057/UNC1151), where PDF lures lead to a ZIP containing a JavaScript loader (OYSTERFRESH) that stores an obfuscated/encrypted payload (OYSTERBLUES) in the Windows Registry and fetches/decodes follow-on code (OYSTERSHUCK) ultimately deploying Cobalt Strike; the report also notes Russian use of AI for targeting and a separate pro-Kremlin Bluesky account-hijacking influence operation (Matryoshka).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
