ESET reported a newly observed FrostyNeighbor campaign targeting governmental organizations in Ukraine with spearphishing emails carrying malicious PDF lures. The actor, also tracked as Ghostwriter, UNC1151, UAC-0057, TA445, PUSHCHA, and Storm-0257, used a document impersonating Ukrtelecom that linked victims to infrastructure performing server-side geographic filtering. Non-Ukrainian visitors received a benign decoy PDF, while Ukrainian IP addresses were served a malicious RAR archive, indicating deliberate target validation and a continued espionage focus on Ukraine and neighboring Eastern European states.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-21, CERT-UA reported a phishing campaign active since spring 2026 targeting Ukrainian government organizations via compromised email accounts and Prometheus certificate-themed lures. The advisory described a malware chain using OYSTERFRESH, OYSTERBLUES, and OYSTERSHUCK, assessed the activity as typical of UAC-0057/UNC1151, and noted possible later-stage Cobalt Strike delivery.
On 2026-05-14, ESET publicly reported the newly discovered FrostyNeighbor activity and linked it to the long-running cyberespionage actor also tracked as Ghostwriter, UNC1151, UAC-0057, TA445, PUSHCHA, and Storm-0257. The report highlighted the group's evolving tooling and continued focus on Ukraine and neighboring Eastern European countries.
On 2026-05-07, ESET Research published indicators of compromise for the FrostyNeighbor campaign, including lure files, JavaScript stages, PicassoLoader components, Cobalt Strike infrastructure, and ATT&CK mappings. The IoCs documented command-and-control domains and other artifacts first observed during the March-April 2026 activity targeting Ukrainian government organizations.
In the observed March 2026 activity, Ukrainian victims were served a malicious RAR archive containing JavaScript stages, including a PicassoLoader variant that fingerprinted hosts and beaconed to attacker infrastructure every 10 minutes. After likely manual operator validation, the attackers deployed a Cobalt Strike dropper that masqueraded as Viber software and established persistence via registry Run keys and LNK execution.
Beginning in March 2026, ESET observed FrostyNeighbor targeting governmental organizations in Ukraine with spearphishing emails carrying malicious PDF attachments. The campaign used a lure impersonating Ukrtelecom and infrastructure that served different content based on the victim's geographic location.
Between 2024-07-12 and 2024-07-18, CERT-UA observed increased UAC-0057 activity using macro-enabled lure documents on local self-government reform, USAID/DAI HOVERLA, taxation, and financial-economic themes to infect Ukrainian local self-government bodies. The documents executed PICASSOLOADER to deliver Cobalt Strike Beacon, and CERT-UA published file, network, and host-based indicators for the campaign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 200 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
10 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcetherecord.media
Open sourcesecurityaffairs.com
Open sourcewelivesecurity.com
Open sourcegithub.com
Open sourcecert.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.