Ghostwriter APT Targets Ukrainian Government With Geofenced PDF Phishing and Cobalt Strike
ESET Research on May 14 attributed new FrostyNeighbor activity since March 2026 to spear-phishing campaigns delivering malicious PDFs that impersonate Ukrainian telecommunications provider Ukrtelecom and target government, military, and defense organizations in Ukraine. The lure PDFs link to an attacker-controlled server that performs a geofencing check, returning a benign decoy to non-Ukrainian connections while delivering a RAR archive containing a JavaScript PicassoLoader downloader to Ukrainian-sourced requests. PicassoLoader fingerprints the compromised host and beacons system data to C2 infrastructure every ten minutes; ESET assessed that operators
Operator-gated Cobalt Strike delivery, held pending manual PicassoLoader fingerprint review, signals FrostyNeighbor is treating Ukrainian government network access as operationally scarce (ESET Research, corroborated by two secondary outlets). That discipline may instead reflect a small team managing its own triage burden rather than elevated targeting doctrine. FrostyNeighbor will
4 sources
- Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike -
The Hacker News - FrostyNeighbor: Fresh mischief and digital shenanigans -
ESET WeLiveSecurity - 'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine -
Dark Reading - Belarus-aligned FrostyNeighbor attacks Ukrainian government, again — ESET Research discovers -
GlobeNewswire / ESET