Belarus-Linked Ghostwriter Group Launches OysterFresh Campaign Against Ukrainian Government Using Prometheus Platform Lures
CERT-UA reported this week that
The convergence of two Ghostwriter chains on Cobalt Strike indicates Belarus state intelligence pursuing persistent access inside Ukrainian government networks rather than episodic disruption. The Prometheus lure exploits a platform government employees genuinely use, raising click rates above generic phishing, while FrostyNeighbor's server-side IP geo-filtering defeats sandbox detonation and slows detection timelines. CERT-UA's wscript.exe restriction addresses the OYSTERFRESH delivery chain but leaves the FrostyNeighbor RAR-delivered JavaScript variant requiring separate detection logic. The overlap could equally reflect two independent Belarusian collection cells updating existing toolkits rather than centrally directed intensification. ESET Research is the sole primary source; secondary outlets amplify without independent collection.
6 sources
- Ghostwriter Is Back, Using a Ukrainian Learning Platform as Bait to Hit Government Targets -
Security Affairs - Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware -
The Hacker News - Belarus-linked hackers use fake training certificates to target Ukrainian officials -
The Record from Recorded Future News - Belarus-aligned FrostyNeighbor attacks Ukrainian government, again — ESET Research discovers
- FrostyNeighbor: Fresh mischief and digital shenanigans -
ESET Research (WeLiveSecurity) - Точковий сплеск активності UAC-0057 (CERT-UA#10340)