{"id":542355,"date":"2026-05-14T19:06:15","date_gmt":"2026-05-14T16:06:15","guid":{"rendered":"https:\/\/reform.news\/?p=542355"},"modified":"2026-05-14T21:10:39","modified_gmt":"2026-05-14T18:10:39","slug":"belarus-linked-ghostwriter-group-updates-cyberattack-tools-targeting-ukrainian-state-bodies","status":"publish","type":"post","link":"https:\/\/reform.news\/en\/belarus-linked-ghostwriter-group-updates-cyberattack-tools-targeting-ukrainian-state-bodies","title":{"rendered":"Belarus-Linked Ghostwriter Group Updates Cyberattack Tools Targeting Ukrainian State Bodies"},"content":{"rendered":"<div id=\"fb-root\"><\/div>\n<p>Researchers at ESET have identified new activity by the hacker group FrostyNeighbor, also known as Ghostwriter, UNC1151, UAC-0057, TA445, PUSHCHA or Storm-0257, WeLiveSecurity <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/frostyneighbor-fresh-mischief-digital-shenanigans\/\">writes<\/a>. The group is believed to operate from Belarus and has reportedly been active since at least 2016.<\/p>\n<p>According to the researchers, since March 2026 the group has been conducting targeted phishing attacks against Ukrainian government organisations using an updated infection scheme. Victims receive PDF files disguised as documents from the Ukrainian operator Ukrtelecom. When a link in the document is opened, the system checks the user\u2019s IP address. If the address is located in Ukraine, instead of a harmless file the victim downloads a malicious RAR archive containing the PicassoLoader JavaScript loader.<\/p>\n<p>The loader collects data about the infected computer \u2014 including the username, operating system version and list of running processes \u2014 and sends it to the attackers\u2019 server every 10 minutes. The decision to deliver the final malicious payload is made manually by the operators based on the collected data. If the victim is deemed of interest, a Cobalt Strike beacon is deployed on the computer, giving the attackers full control over the system.<\/p>\n<p>The group continues to target primarily Ukraine, Poland and Lithuania, focusing on government agencies, the defence sector, industry, healthcare and logistics. According to ESET, FrostyNeighbor demonstrates a high level of operational maturity and regularly updates its arsenal to evade detection systems.<\/p>\n<p><i>\u201cFrostyNeighbor remains a resilient and adaptive threat actor, demonstrating a high level of operational maturity through the use of diverse lure documents, evolving lure and loader variants, and novel delivery mechanisms. This latest attack chain we uncovered continues the group\u2019s efforts to refresh and expand its arsenal while attempting to evade detection in order to compromise its targets,\u201d<\/i> the report states.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers at ESET have identified new activity by the hacker group FrostyNeighbor, also known as Ghostwriter, UNC1151, UAC-0057, TA445, PUSHCHA or Storm-0257, WeLiveSecurity writes. The group is believed to operate from Belarus and has reportedly been active since at least 2016. According to the researchers, since March 2026 the group has been conducting targeted phishing [&hellip;]<\/p>\n","protected":false},"author":119,"featured_media":500805,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_sharing_image":{"poster":"https:\/\/reform.news\/wp-content\/uploads\/2026\/05\/6a061022a6d2a.jpg","width":1200,"height":630,"template":"691142dd","mode":"auto"},"_sharing_image_fieldset":{"dTVKfmI95PYT":"Belarus-Linked Ghostwriter Group Updates Cyberattack Tools Targeting Ukrainian State Bodies"},"footnotes":""},"categories":[142339,143128],"tags":[],"class_list":["post-542355","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-main","category-computers"],"wps_subtitle":"","_links":{"self":[{"href":"https:\/\/reform.news\/en\/wp-json\/wp\/v2\/posts\/542355","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/reform.news\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/reform.news\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/reform.news\/en\/wp-json\/wp\/v2\/users\/119"}],"replies":[{"embeddable":true,"href":"https:\/\/reform.news\/en\/wp-json\/wp\/v2\/comments?post=542355"}],"version-history":[{"count":0,"href":"https:\/\/reform.news\/en\/wp-json\/wp\/v2\/posts\/542355\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/reform.news\/en\/wp-json\/wp\/v2\/media\/500805"}],"wp:attachment":[{"href":"https:\/\/reform.news\/en\/wp-json\/wp\/v2\/media?parent=542355"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/reform.news\/en\/wp-json\/wp\/v2\/categories?post=542355"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/reform.news\/en\/wp-json\/wp\/v2\/tags?post=542355"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}