Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors FrostyNeighbor

Also known as: Ghostwriter, UNC1151, TA445, PUSHCHA, Storm-0257, UAC 0057, Sandworm Team

Description

FrostyNeighbor operates as a state‑oriented threat actor employing a layered approach of initial access, exploitation, and persistence. Its spearphishing repertoire centers on malicious PDFs, MS Office documents, and webmail XSS exploits that embed JavaScript downloaders, notably the multi‑variant PicassoLoader implemented in .NET, PowerShell, C++, and JavaScript. Once executed, the loader typically fetches a Cobalt Strike beacon—often disguised as legitimate images or CSS/JS files—to establish a resilient command–and–control channel over HTTPS. The group complements social engineering with exploitation of documented CVEs (WinRAR CVE‑2023‑38831, Roundcube CVE‑2024‑42009 XSS, and WPS Office RCE), enabling credential harvesting and system compromise without user interaction. Persistence is achieved through scheduled tasks, registry Run keys, and Startup folder entries, while attackers employ legitimate cloud services (e.g., Slack) and Canarytoken tokens for delivery pipelines and victim monitoring. Beyond data theft, FrostyNeighbor orchestrates cyber‑enabled disinformation campaigns targeting the North Atlantic Alliance. The actor’s operational tempo reflects an adaptive toolchain—integrating stolen Cobalt Strike binaries with custom shells—and demonstrates a clear synergy between espionage objectives and political messaging aligned with Belarusian interests.

Goals & Targeting

Targeted Sectors

Government
Defense
Healthcare
Manufacturing
Communications
Pharmaceutical
Non profit
Telecommunications
Transportation
Financial services
Education
Energy
Nuclear
Chemical
Hospitality
Aerospace
Think tank

Targeted Countries / Regions

Lithuania
Poland
Ukraine
BY
UA
PL
RU
CN
US
FR
IR
KZ
IL
IQ
AZ
KR

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 2 days ago

Executive Summary

FrostyNeighbor, also known as Ghostwriter and other aliases, is a Belarus‑aligned APT that conducts sophisticated espionage primarily against Ukrainian, Polish, and Lithuanian targets. The group blends spearphishing with zero‑day exploitation (e.g., WinRAR CVE‑2023‑38831) and leverages the JavaScript downloader PicassoLoader to deliver Cobalt Strike implants, supporting long‑term influence and disinformation campaigns aimed at NATO allies.

Goals & Targeting

FrostyNeighbor seeks to acquire actionable intelligence from high‑value targets such as government agencies, defense contractors, healthcare institutions, and think tanks in Eastern Europe, the United States, and other NATO member states. Its targeting profile prioritizes entities involved in national security, energy infrastructure, and policy formulation around Ukraine, aiming to influence public perception while harvesting strategic information that supports Belarusian geopolitical objectives.

Enhanced Description

Key Capabilities

  • Spearphishing with malicious PDFs and Office documents containing embedded JavaScript downloaders
  • Use of PicassoLoader JavaScript downloader delivered via disguised file types or within PDF attachments
  • Delivery of Cobalt Strike beacon as payload, including custom implant generation from leaked Cobalt Strike
  • Obfuscated/packed staged payloads to evade detection (T1027.009)
  • Exploitation of zero‑day and public CVEs such as WinRAR CVE‑2023‑38831, Roundcube CVE‑2024‑42009 XSS, WPS Office RCE
  • Utilization of legitimate services (Slack, Canarytokens) for delivery and victim tracking
  • Persistence via scheduled tasks, Run key, and Startup folder, plus account manipulation
  • Command & Control over HTTPS/application‑layer protocols, leveraging disposable domains

ATT&CK Techniques

Discovery
1 technique
Impact
1 technique
Privilege Escalation
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 7 SHA-1 Hash 13

References

  1. www.eset.com — Cited by web research for: TA445
  2. attack.mitre.org — Cited by web research for: Sandworm Team
  3. attack.mitre.org — Cited by web research for: Interception
  4. www.welivesecurity.com — Cited by web research for: Beacon
  5. www.welivesecurity.com — Cited by web research for: Financial Services

Intel Summary

40

Techniques

40

Tools

0

Campaigns

44

IOCs

0

Observed Data

14

Tactics

Tags

APT
Zero-Day Exploitation
Government Targeting
G0vega
Influence Operations
Disinformation
Eastern Europe

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
B
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.