Threats & Adversaries · APT / Espionage

Ghostwriter Adds Registry Persistence to Prometheus Lures

Ghostwriter’s Prometheus emails are more than brand impersonation now. The bigger break is that the campaign uses compromised mail accounts and a registry-resident payload chain, which makes the messages look like legitimate internal traffic and leaves behind persistence after the lure file is gone.

CERT-UA says the campaign has run since spring 2026 against Ukrainian government entities. The current chain drops OYSTERFRESH, writes encrypted OYSTERBLUES into the Windows Registry, and launches OYSTERSHUCK to decode it; the malware also collects system data and can load a next-stage payload, with the final stage assessed as Cobalt Strike.

That shifts the risk from obvious phishing to a mailbox-and-endpoint trust problem. If defenders only hunt the attachment or the fake certificate theme, they can miss the compromised sender and the registry-based foothold that survives simple file cleanup.

2 sources · May 22

Timeline

Sources

Part of the PlainSec briefing for 2026-05-23

Every edition of this story: Ghostwriter Adds Registry Persistence to Prometheus Lures

More from today