Threats · 115 days ago
Ghostwriter’s Prometheus emails are more than brand impersonation now. The bigger break is that the campaign uses compromised mail accounts and a registry-resident payload chain, which makes the messages look like legitimate internal traffic and leaves behind persistence after the lure file is gone.
CERT-UA says the campaign has run since spring 2026 against Ukrainian government entities. The current chain drops OYSTERFRESH, writes encrypted OYSTERBLUES into the Windows Registry, and launches OYSTERSHUCK to decode it; the malware also collects system data and can load a next-stage payload, with the final stage assessed as Cobalt Strike.
That shifts the risk from obvious phishing to a mailbox-and-endpoint trust problem. If defenders only hunt the attachment or the fake certificate theme, they can miss the compromised sender and the registry-based foothold that survives simple file cleanup.
2 sources covering this story
Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware
Ghostwriter used Prometheus lures since spring 2026 to target Ukraine agencies, enabling malware delivery and data theft.
The Record from Recorded Future
Belarus-linked hackers use fake training certificates to target Ukrainian officials
A Belarus-linked hacking group known as GhostWriter has launched a new espionage campaign against Ukrainian government officials using fake emails disguised as messages from a popular online learning platform to deliver malware.
Part of the PlainSec briefing for 2026-05-23