logo

Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware

ID: 77eceb20-cccf-5fd9-a46d-e4d128e406c4

STIX ID: report--77eceb20-cccf-5fd9-a46d-e4d128e406c4

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: [email protected] (The Hacker News)

...
...

CERT-UA attributes a spring-2026 phishing campaign targeting Ukrainian government entities to the Belarus-aligned APT Ghostwriter (UAC-0057/UNC1151), where PDF lures lead to a ZIP containing a JavaScript loader (OYSTERFRESH) that stores an obfuscated/encrypted payload (OYSTERBLUES) in the Windows Registry and fetches/decodes follow-on code (OYSTERSHUCK) ultimately deploying Cobalt Strike; the report also notes Russian use of AI for targeting and a separate pro-Kremlin Bluesky account-hijacking influence operation (Matryoshka).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.