Also known as: Ghostwriter, UNC1151, TA445, PUSHCHA, Storm-0257, UAC 0057, Sandworm Team
FrostyNeighbor operates as a state‑oriented threat actor employing a layered approach of initial access, exploitation, and persistence. Its spearphishing repertoire centers on malicious PDFs, MS Office documents, and webmail XSS exploits that embed JavaScript downloaders, notably the multi‑variant PicassoLoader implemented in .NET, PowerShell, C++, and JavaScript. Once executed, the loader typically fetches a Cobalt Strike beacon—often disguised as legitimate images or CSS/JS files—to establish a resilient command–and–control channel over HTTPS. The group complements social engineering with exploitation of documented CVEs (WinRAR CVE‑2023‑38831, Roundcube CVE‑2024‑42009 XSS, and WPS Office RCE), enabling credential harvesting and system compromise without user interaction. Persistence is achieved through scheduled tasks, registry Run keys, and Startup folder entries, while attackers employ legitimate cloud services (e.g., Slack) and Canarytoken tokens for delivery pipelines and victim monitoring. Beyond data theft, FrostyNeighbor orchestrates cyber‑enabled disinformation campaigns targeting the North Atlantic Alliance. The actor’s operational tempo reflects an adaptive toolchain—integrating stolen Cobalt Strike binaries with custom shells—and demonstrates a clear synergy between espionage objectives and political messaging aligned with Belarusian interests.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
FrostyNeighbor, also known as Ghostwriter and other aliases, is a Belarus‑aligned APT that conducts sophisticated espionage primarily against Ukrainian, Polish, and Lithuanian targets. The group blends spearphishing with zero‑day exploitation (e.g., WinRAR CVE‑2023‑38831) and leverages the JavaScript downloader PicassoLoader to deliver Cobalt Strike implants, supporting long‑term influence and disinformation campaigns aimed at NATO allies.
Goals & Targeting
FrostyNeighbor seeks to acquire actionable intelligence from high‑value targets such as government agencies, defense contractors, healthcare institutions, and think tanks in Eastern Europe, the United States, and other NATO member states. Its targeting profile prioritizes entities involved in national security, energy infrastructure, and policy formulation around Ukraine, aiming to influence public perception while harvesting strategic information that supports Belarusian geopolitical objectives.
Enhanced Description
Key Capabilities
No campaigns linked yet.
No observed data linked yet.
40
Techniques
40
Tools
0
Campaigns
44
IOCs
0
Observed Data
14
Tactics