Adversary Intelligence — 2026-05-23

Belarus-Linked Ghostwriter Group Launches OysterFresh Campaign Against Ukrainian Government Using Prometheus Platform Lures

BLUFBelarus is investing in durable espionage access inside Ukrainian government networks, with the dual lures and geo-filtered delivery signaling a deliberate effort to outpace CERT-UA's detection and remediation.

CERT-UA reported this week that Ghostwriter (UAC-0057, UNC1151) has been phishing Ukrainian government organizations since spring 2026, using emails from compromised accounts that impersonate Prometheus, a Ukrainian online learning platform used by government employees 123. The emails deliver PDF attachments linking to a ZIP archive containing OYSTERFRESH, a JavaScript file that drops an obfuscated payload (OYSTERBLUES) into the Windows Registry and loads a decoder component (OYSTERSHUCK) 12. OYSTERBLUES harvests system fingerprint data and transmits it to Cloudflare-shielded C2 servers on .icu domains, with CERT-UA assessing Cobalt Strike as the final payload 13. ESET Research separately documented FrostyNeighbor activity from March 2026 using a Ukrtelecom-themed lure and a JavaScript PicassoLoader variant, with server-side IP validation delivering the malicious archive only to Ukrainian-geolocated systems 4. ESET further identified concurrent FrostyNeighbor targeting of Poland and Lithuania, where victimology extends beyond military and government to industrial, manufacturing, healthcare, pharmaceuticals, and logistics sectors 4.

Analysis
The convergence of two Ghostwriter chains on Cobalt Strike indicates Belarus state intelligence pursuing persistent access inside Ukrainian government networks rather than episodic disruption. The Prometheus lure exploits a platform government employees genuinely use, raising click rates above generic phishing, while FrostyNeighbor's server-side IP geo-filtering defeats sandbox detonation and slows detection timelines. CERT-UA's wscript.exe restriction addresses the OYSTERFRESH delivery chain but leaves the FrostyNeighbor RAR-delivered JavaScript variant requiring separate detection logic. The overlap could equally reflect two independent Belarusian collection cells updating existing toolkits rather than centrally directed intensification. ESET Research is the sole primary source; secondary outlets amplify without independent collection.
6 sources
  1. Ghostwriter Is Back, Using a Ukrainian Learning Platform as Bait to Hit Government Targets - Security Affairs
  2. Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware - The Hacker News
  3. Belarus-linked hackers use fake training certificates to target Ukrainian officials - The Record from Recorded Future News
  4. Belarus-aligned FrostyNeighbor attacks Ukrainian government, again — ESET Research discovers
  5. FrostyNeighbor: Fresh mischief and digital shenanigans - ESET Research (WeLiveSecurity)
  6. Точковий сплеск активності UAC-0057 (CERT-UA#10340)

View in full brief →

UNCLASSIFIED // OPEN SOURCE