The images in this article were generated with artificial intelligence. How we publish
A Belarusian-aligned actor known as Ghostwriter (also referred to as UAC-0057 or UNC1151 in various reports) has reactivated a speech-phishing campaign against Ukrainian government agencies, taking advantage of lures related to the Prometheus educational platform. According to public alerts from the Ukrainian response team, attackers send emails from committed accounts to a PDF that leads to the download of a ZIP with a JavaScript file that acts as the first step of a modular malware chain.
The technique described combines a classic social engineering with abuses of Windows execution mechanisms: the initial JavaScript, identified in reports like OYSTERFRESH, shows a decoy document while writing in the Windows Registry an osfuscated and encrypted binary (OYSTERBLUES) and downloading a decoder (OYSTERSHUCK) that finally activates the payload. This flow allows the attacker to collect system and process information, exfilter it via HTTP and expect next-stage code that is dynamically executed by eval (). The analysis points out that the final phase uses Cobalt Strike, a legitimate adversary simulation tool that is now massively used for post-malicious exploitation.

This case illustrates a number of lessons that should be highlighted: the combination of legitimate committed accounts and apparently harmless files remains one of the most effective forms of penetration, and the execution of dynamic code in endpoints makes it easier for an attacker to improvise later stages without leaving static prints easy to detect. In addition, modularity (multiple components with similar names) and the use of performance-time assessments make it difficult for traditional signature-based detection.
In the strategic context, Ukrainian authorities also warn about the incorporation of artificial intelligence tools by attackers to track targets and generate malicious commands in real time, adding an automation and scaling layer in cyberintelligence and influence operations. I mean, not only is access sought, but a sustained presence that serves both for espionage and for disinformation operations. The CERT-Ukraine website is available for information on local alerts and mitigation. https: / / cert.gov.ua /.
From the operational point of view, the basic recommendations suggested by experts and response teams should be priority: to restrict the use of wscript.exe for standard accounts (e.g. with AppLocker or Windows Defender Application Control), to block the execution from time and user locations, and to apply execution controls that prevent the execution of attached scripts by unauthorized users. The simplicity of these measures contrasts with their high impact on reducing the attack surface.
In addition, it is key to strengthen hygiene in account management: to eliminate compromised access, to force the reset of credentials, to enable robust multifactor authentication, to review and limit exposed RDP / VPN sessions, and to monitor abnormal login patterns. Public and private organizations should also prioritize the visualization of outgoing HTTP traffic to unusual domains and IP, as C2s in these campaigns often abuse simple web channels that overlook basic filtering controls.
In the detection and response layer, it is appropriate to deploy EDR / NDI capabilities that identify eval () executions in processes that do not normally use them, memory decoding chains and unusual scriptures in the Register. Endpoint instrumentation to capture child processes and outgoing connections, along with roulesets that alert about Cobalt Strike-associated behavior, allows for the detection of intermediate phases before the opponent sets up long-term persistence. The initiative of the US Cyber Security Agency is available for practical guidance on preparedness and response to persistent national threats. United States https: / / www.cisa.gov / shields-up.

The problem is not limited to technical malware: the same influence and manipulation campaign that exploits legitimate accounts on social platforms - as seen with actual account hijackings on emerging networks - shows that the exploitation of identities is a direct political impact vector. Social services and journalists must consider the protection of accounts (2FA, active sessions, access notifications) and recovery processes that allow for revalidation of identity before a third party publishes on its behalf. The Bluesky network, for example, has intervened by suspending committed accounts until the headlines can re-establish control; more information on the platform on https: / / bsky.app /.
For security officials, my editorial recommendation is not to wait for the detection of the next wave: implement scripts execution restrictions, tighten account and telemetry controls, and integrate threat intelligence into automated locking flows. At the organizational level, train key users on targeted phishing and review the software supply chain to avoid unlicensed or backdoor package facilities before they are exploited as an initial vector.
Finally, the increasing use of IA by state and parastatal actors requires an update of the defence frameworks. Defensive automation must accompany the offensive: anomaly-based detection, automated behavior analysis and playbooks that shorten the exposure window after the first hint. Effective security today is a mixture of consistent basic measures and rapid response capacity when an intrusion tries to move from recognition to sustained presence and influence operations.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...