Socprime GhostShell Malware Targets Ukraine's UAV and Defense Supply Chain
Article Content
- •GhostShell targets Ukraine's UAV and defense supply chain using advanced malware.
- •Attack methods include mTLS implants and Telegram-based loaders for persistence.
- •Immediate isolation and forensic analysis of affected systems are critical for mitigation.
The GhostShell malware cluster is actively targeting Ukraine’s UAV operations and defense supply chain. Utilizing advanced techniques such as mTLS-authenticated implants and Telegram-based loaders, the attackers gain initial access through decoy documents impersonating a Ukrainian drone company. The campaign employs a multi-stage intrusion chain involving VBS scripts and custom malware like 122.exe. The operation has been linked to Vidar infostealer activity within the same infrastructure. Security teams are advised to implement strict mTLS certificate validation and monitor for unauthorized client certificate use. Immediate isolation of affected systems and memory forensics are recommended to identify in-memory implants. Organizations should also review network logs for traffic to specific domains associated with the attack.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track GhostShell in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2026-93425: Dokploy PaaS Critical RCE Leads to Container Root and Host Compromise TheHackerWire / 1d Telemetry Metric Intelligence Detail CVE Identifier CVE-2026-93425 CVSS Severity 9.9 CRITICAL Affected Target the Dokploy container Vulnerability Class Security Vulnerability Exploit Availability No Public PoC Indexed EPSS Threat Score Awaiting scoring CISA KEV Status Not Listed in CISA KEV Remediation Status Advisory / Mitigation In Review A critical command injection vulnerability, CVE-2026
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…