Ghostwriter Adds Registry Persistence to Prometheus Lures

Ghostwriter’s Prometheus emails are more than brand impersonation now. The bigger break is that the campaign uses compromised mail accounts and a registry-resident payload chain, which makes the messages look like legitimate internal traffic and leaves behind persistence after the lure file is gone. CERT-UA says the campaign has run since spring 2026 against Ukrainian government entities. The current chain drops OYSTERFRESH, writes encrypted OYSTERBLUES into the Windows Registry, and launches OYSTERSHUCK to decode it; the malware also collects system data and can load a next-stage payload, with the final stage assessed as Cobalt Strike. That shifts the risk from obvious phishing to a mailbox-and-endpoint trust problem. If defenders only hunt the attachment or the fake certificate theme, they can miss the compromised sender and the registry-based foothold that survives simple file cleanup.

Part of the PlainSec briefing for 2026-05-23

Sources