Welivesecurity FrostyNeighbor Cyberespionage Campaign Targets Ukrainian and Polish Governments
Article Content
- •FrostyNeighbor targets Ukrainian and Polish government organizations using spearphishing.
- •The group employs a JavaScript variant of PicassoLoader to deliver Cobalt Strike payloads.
- •Victim systems are fingerprinted to selectively deploy malware based on geographic location.
The Belarus-aligned cyber group FrostyNeighbor has launched a targeted campaign against government organizations in Ukraine and Poland since March 2026. Utilizing spearphishing techniques, the group delivers malicious payloads through deceptive PDF documents impersonating the Ukrainian telecom provider Ukrtelecom. The attack employs a JavaScript variant of PicassoLoader to facilitate the deployment of Cobalt Strike for post-compromise operations. FrostyNeighbor's tactics include fingerprinting victims' systems to selectively deliver malware based on geographic location, with a focus on military and governmental entities. The group has been active since at least 2016 and continues to evolve its methods to evade detection. Key vulnerabilities exploited include CVE-2024 and CVE-2023-38831. The ongoing threat poses significant risks to national security in the region.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track FrostyNeighbor, Cobalt Strike and Ukrtelecom in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
FamousSparrow Deploys SparroWocky Backdoor in Latin America The China-aligned cyberespionage group FamousSparrow has replaced its previous backdoor, SparrowDoor, with a new malware called SparroWocky, targeting governmental organizations in Latin America since August 2025. ESET Research attributes this campaign to a likely response to increased U.S. interests in the region.…
Emerging EDR Killer Tool Targeting Ransomware Groups A new malicious tool, referred to as the EDR killer, is being actively used by at least eight ransomware groups, including Blacksuit and Medusa, to disable endpoint detection and response (EDR) solutions. This tool is believed to be an evolution of the EDRKillShifter developed by RansomHub, which allows ransomware…