phishing
Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware
High
Summary
The Ghostwriter threat actor, linked to Belarus, has been conducting a phishing campaign targeting Ukrainian government entities since the spring of 2026. This campaign utilizes lures related to the Prometheus online learning platform and employs a multi-stage malware payload, including OYSTERFRESH and OYSTERSHUCK, to steal sensitive information. The activity highlights broader cyber threats targeting Ukraine, including the use of AI and coordinated disinformation campaigns.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
