Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike
ID: 88f35895-3c75-5527-b675-409ee29f8a51
STIX ID: report--88f35895-3c75-5527-b675-409ee29f8a51
Feed Name: The Hacker News
This report summarizes recent, active cyber operations across Eastern Europe: Belarus-aligned Ghostwriter (FrostyNeighbor) has been observed since March 2026 using spear-phishing PDFs that deliver JavaScript PicassoLoader and Cobalt Strike—leveraging CVE-2023-38831 and CVE-2024-42009—to target Ukrainian government, defense, and related sectors; Russia-aligned Gamaredon is deploying GammaDrop/GammaLoad via CVE-2025-8088 against Ukrainian institutions; pro-Ukraine BO Team and financially motivated Hive0117 have conducted separate campaigns against Russian and regional organizations using RATs, remote access tools, and large-scale phishing to steal funds and credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
