← Front PageThreat Intel Desk
Threat Intel
Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike
Belarus-linked Ghostwriter deploys geofenced PDF phishing against Ukrainian government, reflecting sophisticated targeting techniques in ongoing regional cyber warfare.
Summary written by editorial AI · Source link below
The Belarus-aligned threat group known as Ghostwriter has been attributed to a fresh set of attacks targeting governmental organizations in Ukraine. Active since at least 2016, Ghostwriter has been linked to both cyber espionage and influence operations targeting neighboring countries, particularly Ukraine. It's also tracked under the monikers FrostyNeighbor, PUSHCHA, Storm-0257, TA445, UAC‑0057
Continue at the source
Read the full report at THN (Feedburner)External link — opens at THN (Feedburner) in a new tab.
§
Continue with
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d