Ghostwriter Threat Group Targets Ukrainian Government Organizations
Update threat‑intel feeds and monitor for Ghostwriter indicators in Ukrainian government networks.
Update threat‑intel feeds and monitor for Ghostwriter indicators.
Summary
The Belarus‑aligned threat group Ghostwriter has been linked to a fresh wave of attacks against Ukrainian government organizations. Active since at least 2016, Ghostwriter has carried out both cyber espionage and influence operations targeting neighboring countries, especially Ukraine. The group operates under multiple monikers, including FrostyNeighbor, PUSHCHA, Storm‑0257, TA445, and UAC‑0057. Recent activity shows a focus on gathering intelligence from governmental networks. The attribution is based on malware signatures and infrastructure analysis. Ghostwriter’s operations demonstrate a persistent threat to Ukrainian state actors. Security teams should update threat intelligence feeds to include Ghostwriter indicators. The group’s continued activity underscores the ongoing risk to national security infrastructure.
Key changes
- Ghostwriter active since 2016 targeting Ukrainian gov
- Operates under aliases FrostyNeighbor, PUSHCHA, Storm‑0257, TA445, UAC‑0057
- Conducts cyber espionage and influence operations
- Recent attacks focus on intelligence gathering
- Attribution based on malware signatures and infrastructure