Ghostwriter Adds Registry Persistence to Prometheus Lures
Ghostwriter’s Prometheus emails are more than brand impersonation now. The bigger break is that the campaign uses compromised mail accounts and a registry-resident payload chain, which makes the messages look like legitimate internal traffic and leaves behind persistence after the lure file is gone.
CERT-UA says the campaign has run since spring 2026 against Ukrainian government entities. The current chain drops OYSTERFRESH, writes encrypted OYSTERBLUES into the Windows Registry, and launches OYSTERSHUCK to decode it; the malware also collects system data and can load a next-stage payload, with the final stage assessed as Cobalt Strike.
That shifts the risk from obvious phishing to a mailbox-and-endpoint trust problem. If defenders only hunt the attachment or the fake certificate theme, they can miss the compromised sender and the registry-based foothold that survives simple file cleanup.