The Belarus-linked threat group known as Ghostwriterhas been blamed for a new set of attacks targeting government organizations in Ukraine. Active since at least 2016, Ghostwriter has been linked to both cyberespionage and influence operations targeting neighboring countries, particularly Ukraine. It is also tracked under various aliases including FrostyNeighbor, PUSHCHA, Storm-0257, TA445, UAC‑0057, Umbral Bison, UNC1151, and White Lynx.
See also: Spyware researcher uncovers “Signal phishing campaign”

“FrostyNeighbor conducts continuous cyber operations, changing and updating its tool regularly, updating its breach chain and methods to evade detection – targeting victims located in Eastern Europe,” ESET said in a report.
Previous attacks carried out by the hacker group have leveraged a malware family known as PicassoLoader, which acts as a conduit for Cobalt Strike Beacon and njRAT. In late 2023, the threat actor was observed exploiting a vulnerability in WinRAR (CVE-2023-38831, CVSS score: 7.8) to deploy PicassoLoader and Cobalt Strike.
As recently as last year, Polish entities were targeted by a phishing campaign organized by Ghostwriter, which exploited a cross-site flaw in Roundcube (CVE-2024-42009, CVSS score: 9.3) to execute malicious JavaScript responsible for harvesting email login credentials. In some cases, threat actors are said to have leveraged the harvested credentials to analyze mailbox contents, download contact lists, and abuse the compromised account to spread more phishing emails, according to a report from CERT Polska.
See also: Phishing campaign targets ManageWP users via Google Ads

Towards the end of 2025, the team began incorporating an anti-analysis technique where the decoy documents relied on dynamic CAPTCHA checks to trigger the attack chain. “FrostyNeighbor remains a persistent and adaptive threat actor, demonstrating a high level of operational maturity through the use of diverse decoy documents, evolving decoy and downloader variants, and new delivery mechanisms,” said ESET researcher Damien Schaeffer.
The latest activities, observed since March 2026, include the use of links to malicious PDFs sent via spear-phishing attachments to target government entities in Ukraine, ultimately culminating in the deployment of a JavaScript version of PicassoLoader to drop Cobalt Strike.
The PDF decoys have been found to impersonate Ukrainian telecommunications company Ukrtelecom. The infection sequence incorporates a geofencing check, delivering a harmless PDF file to victims whose IP address does not correspond to Ukraine. The embedded link in the PDF document is used to deliver a RAR file containing a JavaScript payload that displays a decoy document to maintain the scam, while simultaneously launching PicassoLoader in the background.
The downloader is also designed to profile and fingerprint the compromised computer, based on which operators can manually decide to send a third-stage JavaScript dropper for the Cobalt Strike Beacon. The system fingerprint is transmitted to the infrastructure controlled by the attacker every 10 minutes, allowing the threat actor to assess whether the victim is of interest.
See also: Microsoft reveals phishing attack on 35,000 users in 26 countries

Activity appears to be focused primarily on military, defense sectors, and government organizations in Ukraine, while victimology in Poland and Lithuania is much broader, targeting industrial and construction sectors, healthcare and pharmaceuticals, logistics, and government sectors.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
