Threats & Adversaries · APT / Espionage

FrostyNeighbor Quietly Filters Targets Before Delivery

FrostyNeighbor has moved from broad spearphishing to operator-vetted delivery. The campaign now validates victims on the server side before sending the final payload, so defenders may see fewer messages even as the espionage operation stays active against high-value government and defense targets.

ESET says the group’s latest activity since March 2026 includes updated tooling and both automated and manual victim checks. The targeting remains centered on Ukrainian government, military, and critical sectors, with related activity in Poland and Lithuania, and still uses CVE-2023-38831 in its delivery chain.

That shift matters because inbox monitoring now misses part of the selection process. The campaign can look low-volume and quiet from the outside while still being used for tailored espionage against regional public-sector targets.

3 sources · May 19

CVE-2023-38831

NVD KEV

Known exploited · CISA KEV

CVSS 7.8 HIGH: rARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. Known ransomware campaign use. EPSS 98% (100th percentile).

CISA federal remediation date Sep 14 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-05-14

Every edition of this story: FrostyNeighbor Quietly Filters Targets Before Delivery

More from today