FrostyNeighbor Quietly Filters Targets Before Delivery
FrostyNeighbor has moved from broad spearphishing to operator-vetted delivery. The campaign now validates victims on the server side before sending the final payload, so defenders may see fewer messages even as the espionage operation stays active against high-value government and defense targets.
ESET says the group’s latest activity since March 2026 includes updated tooling and both automated and manual victim checks. The targeting remains centered on Ukrainian government, military, and critical sectors, with related activity in Poland and Lithuania, and still uses CVE-2023-38831 in its delivery chain.
That shift matters because inbox monitoring now misses part of the selection process. The campaign can look low-volume and quiet from the outside while still being used for tailored espionage against regional public-sector targets.
CVSS 7.8 HIGH: rARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. Known ransomware campaign use. EPSS 98% (100th percentile).
CISA federal remediation date Sep 14 · date passed
Attackers fingerprint victims before delivering spear-phishing mails aimed at espionage in the latest campaign from the Belarus nation-state threat group.
ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group’s continual cyberespionage operations.