Adversary Intelligence — 2026-05-17
Belarus-Linked Ghostwriter Group Launches FrostyNeighbor Campaign Against Ukrainian Government
BLUFGhostwriter's expansion into Polish and Lithuanian defense targets marks this as a NATO-wide threat that geofenced delivery and manual operator triage will keep hidden from automated sandbox defenses.
Observed since at least March 2026, the campaign delivers spear-phishing PDFs containing a download button linking to an actor-controlled server that geofences victims: Ukrainian IP addresses receive a RAR archive with a JavaScript dropper, while all other IPs receive a benign decoy PDF on electronic communications regulations. The JavaScript payload installs a JavaScript-variant PicassoLoader that fingerprints the victim system (username, OS version, running processes) every 10 minutes, enabling manual operator triage before selectively delivering a Cobalt Strike beacon disguised as ViberPC.exe via a renamed rundll32.exe. Persistence is established through scheduled tasks and registry Run keys. Targeting extends beyond Ukrainian government entities to include military and defense sector organizations in Poland and Lithuania.
Analysis
FrostyNeighbor's confirmed targeting of Polish and Lithuanian defense and government organizations obliges NATO-member security services to treat this campaign as an immediate operational threat, not a regionally bounded Ukrainian concern, per ESET WeLiveSecurity (May 14), with no independent technical corroboration. The campaign's geofenced delivery server and manual operator triage architecture render standard sandbox analysis blind to the live infection chain. Automated triage alone will not surface it without geographic replication of victim conditions. The JavaScript PicassoLoader variant reflects deliberate tooling evolution to defeat signatures built against the group's prior .NET and PowerShell loaders. The westward extension may instead reflect subcontracted operator behavior driven by commercial incentive rather than deliberate Belarusian state tasking against NATO members.
2 sources
- ESET details new Ghostwriter activity targeting Ukrainian government - SC World
- Ghostwriter group resumes attacks on Ukrainian Government targets - Security Affairs
View in full brief →