Threats · 115 days ago

Ghostwriter Adds Registry Persistence to Prometheus Lures

Ghostwriter’s Prometheus emails are more than brand impersonation now. The bigger break is that the campaign uses compromised mail accounts and a registry-resident payload chain, which makes the messages look like legitimate internal traffic and leaves behind persistence after the lure file is gone.

CERT-UA says the campaign has run since spring 2026 against Ukrainian government entities. The current chain drops OYSTERFRESH, writes encrypted OYSTERBLUES into the Windows Registry, and launches OYSTERSHUCK to decode it; the malware also collects system data and can load a next-stage payload, with the final stage assessed as Cobalt Strike.

That shifts the risk from obvious phishing to a mailbox-and-endpoint trust problem. If defenders only hunt the attachment or the fake certificate theme, they can miss the compromised sender and the registry-based foothold that survives simple file cleanup.

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-05-23

Editions

Related stories