Adversary Intelligence — 2026-05-14

Ghostwriter APT Targets Ukrainian Government With Geofenced PDF Phishing and Cobalt Strike

BLUFOperator-gated Cobalt Strike delivery signals FrostyNeighbor views Ukrainian government access as scarce, and additional intrusions against those entities are likely within the next six months.

ESET Research on May 14 attributed new FrostyNeighbor activity since March 2026 to spear-phishing campaigns delivering malicious PDFs that impersonate Ukrainian telecommunications provider Ukrtelecom and target government, military, and defense organizations in Ukraine. The lure PDFs link to an attacker-controlled server that performs a geofencing check, returning a benign decoy to non-Ukrainian connections while delivering a RAR archive containing a JavaScript PicassoLoader downloader to Ukrainian-sourced requests. PicassoLoader fingerprints the compromised host and beacons system data to C2 infrastructure every ten minutes; ESET assessed that operators likely decide manually whether to push a third-stage Cobalt Strike payload based on that data. The Hacker News and Dark Reading corroborated the findings and identified Poland and Lithuania as additional targets with broader sectoral scope.

Analysis
Operator-gated Cobalt Strike delivery, held pending manual PicassoLoader fingerprint review, signals FrostyNeighbor is treating Ukrainian government network access as operationally scarce (ESET Research, corroborated by two secondary outlets). That discipline may instead reflect a small team managing its own triage burden rather than elevated targeting doctrine. FrostyNeighbor will likely conduct additional cyberattacks against Ukrainian government entities within the next six months, backed by active Cloudflare-masked C2 and a new PicassoLoader variant. Ukraine operations track a narrow intelligence-collection mandate while Poland and Lithuania campaigns span healthcare, logistics, and manufacturing, a distinct access-accumulation objective. Whether CERT-UA sustains threat-hunting against the live C2 or reallocates to competing threats turns on which reading holds.
4 sources
  1. Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike - The Hacker News
  2. FrostyNeighbor: Fresh mischief and digital shenanigans - ESET WeLiveSecurity
  3. 'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine - Dark Reading
  4. Belarus-aligned FrostyNeighbor attacks Ukrainian government, again — ESET Research discovers - GlobeNewswire / ESET

View in full brief →

UNCLASSIFIED // OPEN SOURCE