Find notable cyber news and cases, enriched with sources, timelines, and signals.

Ghostwriter geofenced PDF spear-phishing campaign targeting Ukrainian government entities

Campaign
First reported
Last updated
Happening score
H score 50
1 unique sources, 1 articles

Summary

Hide ▲

The Ghostwriter / FrostyNeighbor group is running a geofenced spear-phishing campaign against government entities in Ukraine, and the operation matters because it delivers a loader chain that can culminate in Cobalt Strike access. The current wave has been observed since March 2026 and uses malicious PDFs that impersonate Ukrtelecom. Victims outside Ukraine are served benign content, while Ukrainian targets are routed into the attack chain.

Related Happenings

Ghostwriter Prometheus-themed phishing campaign targeting Ukraine government organizations

Campaign
H score33 First: 22.05.2026 19:20 Last: 22.05.2026 19:20 Sources 1

About this happening: A Ghostwriter phishing campaign is targeting Ukraine government organizations with Prometheus-themed lures, increasing the risk of credential theft and follow-on acces...

Gentlemen ransomware affiliate campaign expanding toolkit and infrastructure

Campaign
H score53 First: 20.04.2026 23:02 Last: 20.04.2026 23:02 Sources 1

About this happening: The Gentlemen ransomware campaign now spans a December 29, 2025 attack on Oltenia Energy Complex and later analysis of its evolving infrastructure. The company said so...

APT28 long-term espionage campaign targeting Ukrainian military personnel

Campaign
H score32 First: 10.03.2026 12:55 Last: 10.03.2026 12:55 Sources 1

About this happening: A sustained APT28 espionage campaign is using BEARDSHELL and COVENANT to surveil Ukrainian military personnel, extending access through cloud-based C2 and incr...

Silver Dragon intrusion and phishing campaign targeting Europe, Southeast Asia, and Uzbekistan

Campaign
H score36 First: 04.03.2026 10:14 Last: 04.03.2026 10:14 Sources 1

About this happening: The Silver Dragon campaign is actively using public-facing internet servers and phishing emails with malicious attachments to gain initial access, expanding risk acros...

Dust Specter Iraq Foreign Affairs AI impersonation campaign

Campaign
H score33 First: 03.03.2026 12:30 Last: 03.03.2026 12:30 Sources 1

About this happening: Dust Specter targeted Iraqi government officials in a January 2026 campaign that used impersonation, AI tools, and compromised infrastructure to deliver malici...

Timeline

  1. 14.05.2026 17:00 1 articles · 2mo ago

    Ghostwriter geofenced PDF spear-phishing campaign targeting Ukrainian government entities

    Initial Disclosure

    The campaign's current phase began since March 2026 with malicious PDFs delivered through spear phishing and disguised as Ukrtelecom content. The initial delivery is geofenced, serving benign material outside Ukraine while steering Ukrainian victims into a loader chain.

    Show sources