logo

Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike

ID: 88f35895-3c75-5527-b675-409ee29f8a51

STIX ID: report--88f35895-3c75-5527-b675-409ee29f8a51

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: [email protected] (The Hacker News)

...
...

This report summarizes recent, active cyber operations across Eastern Europe: Belarus-aligned Ghostwriter (FrostyNeighbor) has been observed since March 2026 using spear-phishing PDFs that deliver JavaScript PicassoLoader and Cobalt Strike—leveraging CVE-2023-38831 and CVE-2024-42009—to target Ukrainian government, defense, and related sectors; Russia-aligned Gamaredon is deploying GammaDrop/GammaLoad via CVE-2025-8088 against Ukrainian institutions; pro-Ukraine BO Team and financially motivated Hive0117 have conducted separate campaigns against Russian and regional organizations using RATs, remote access tools, and large-scale phishing to steal funds and credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.