Minacce e avversari · Spionaggio APT
Le email di Prometheus di Ghostwriter non sono più solo impersonificazione del brand. La rottura più importante è che la campagna utilizza account di posta compromessi e una catena di payload residente nel Registry, il che fa sembrare i messaggi come traffico interno legittimo e lascia dietro di sé persistenza dopo che il file esca è scomparso.
2 fonti · 22 mag
The Hacker News
Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware
Ghostwriter used Prometheus lures since spring 2026 to target Ukraine agencies, enabling malware delivery and data theft.
originaleThe Record from Recorded Future
Belarus-linked hackers use fake training certificates to target Ukrainian officials
A Belarus-linked hacking group known as GhostWriter has launched a new espionage campaign against Ukrainian government officials using fake emails disguised as messages from a popular online learning platform to deliver malware.
originalePart of the PlainSec briefing for 2026-05-23
Every edition of this story: Ghostwriter Aggiunge la Persistenza nel Registry ai Lure di Prometheus