Belarus APT Filters Targets Before Spearphishing Govs
This campaign is not mass phishing. FrostyNeighbor fingerprints government targets first, then sends tailored spearphishing, so generic email blocking and broad awareness training miss the real selection step. That makes the operation harder to spot and more consistent with espionage than with commodity fraud.
Reporting from Dark Reading says the Belarus-linked group is now focusing on government organizations in Poland and Ukraine. The targeting pattern matches cross-border intelligence collection against neighboring states, not indiscriminate email spraying.
The risk is selective delivery: defenders may see only a few messages, but those messages are chosen to look credible and land on higher-value officials or adjacent public-sector staff. That kind of pretexting can persist even if overall mail volume stays low.