Researchers have identified a new intrusion cluster, GhostShell (MB-0009), targeting Ukraine’s drone operations, military units, suppliers, and volunteer organizations with lures themed around the legitimate drone company Besomar. The campaign has reportedly been active since at least February 2026 and relies on a malicious archive, Besomar_documentation.rar, containing Ukrainian-language decoy PDFs tailored to procurement, technical, military, and volunteer audiences. Reports say the archive exploits CVE-2025-8088 and CVE-2025-6218, installs a hidden script in the Windows Startup folder for persistence, and retrieves additional payloads from cloudaxis[.]cc.
The operation uses multiple malware components and layered command-and-control methods to hinder detection. Files including 122.exe, 22.exe, and update.exe were linked to the activity: 122.exe performs espionage tasks such as host identification and screenshot capture before sending data to cdnexpress[.]cc; 22.exe deploys Vidar v2 to steal browser credentials, browsing history, and cryptocurrency wallet data; and update.exe masquerades as a Windows security service while using the Telegram dead-drop t[.]me/flufff6262 to resolve live infrastructure. Researchers also reported an in-memory implant secured with mutual TLS and certificates issued by "GhostShell Implant CA", and said the group appears highly organized, though attribution to a specific nation-state remains unconfirmed.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Synaptic Systems/Synaptic Security reported that the newly tracked GhostShell (MB-0009) campaign has been active since at least February 2026, targeting Ukraine's drone operations, defense supply chain, military units, and volunteer groups. The activity used Besomar-themed lures and malware delivery infrastructure against organizations in Ukraine's UAV ecosystem.
On June 24, 2026, Synaptic Systems/Synaptic Security publicly identified the GhostShell (MB-0009) cluster and disclosed technical details of its tooling, including Besomar_documentation.rar, startup-folder persistence, an mTLS implant, a Telegram dead-drop resolver, and Vidar v2 deployment. The researchers said attribution to a specific nation-state would be premature and currently track GhostShell as an independent, highly organized cybercriminal group.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 27 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcecybersecuritynews.com
Open sourceblog.synapticsystems.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.