← Front PageThreat Intel Desk
Threat Intel
Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike
Belarus-linked Ghostwriter deploys geofenced PDF phishing against Ukrainian government, reflecting sophisticated targeting techniques in ongoing regional cyber warfare.
Summary written by editorial AI · Source link below
The Belarus-aligned threat group known as Ghostwriter has been attributed to a fresh set of attacks targeting governmental organizations in Ukraine. Active since at least 2016, Ghostwriter has been linked to both cyber espionage and influence operations targeting neighboring countries, particularly Ukraine. It's also tracked under the monikers FrostyNeighbor, PUSHCHA, Storm-0257, TA445, UAC‑0057
Continue at the source
Read the full report at THN (Feedburner)External link — opens at THN (Feedburner) in a new tab.
§
Continue with
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters4d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication5d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner5d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials5d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain5d