Belarus's Oldest Digital Weapon Returns to Kyiv- 215
June 28, 2026
Nearly a decade into its operational life, the Belarus-aligned threat group known as Ghostwriter has not needed to reinvent itself so much as refine what already works. A new campaign documented by ESET researchers, active since March 2026, shows the group returning to a familiar target with a familiar lure and a slightly sharpened set of tools, proof that in state-aligned cyberespionage, patience and iteration often outperform novelty.
The operation, which ESET attributes to FrostyNeighbor, the group also known as UNC1151, UAC-0057, and Storm-0257 among other designations, opens with a spearphishing email carrying a PDF that impersonates Ukrtelecom, one of Ukraine's principal telecommunications providers. The lure promises reassurance about customer data protection and offers a download button, styled convincingly enough to pass as routine corporate correspondence. What happens next depends entirely on where the click originates. Victims connecting from outside Ukraine are shown a harmless decoy, an authentic-looking regulatory document that gives investigators outside the country nothing to work with. Only Ukrainian IP addresses trigger the real payload: a RAR archive containing a JavaScript loader that displays the same decoy PDF as cover while quietly launching PicassoLoader, the group's long-serving downloader, now rewritten in JavaScript after previous incarnations in .NET, PowerShell, and C++.
PicassoLoader's role is reconnaissance rather than damage. It profiles the compromised machine, collecting the username, hostname, operating system version, boot time, and running process list, and reports back to the operators' infrastructure every ten minutes. Crucially, what happens after that is not automated. ESET's researchers describe the decision to escalate as a manual one, made by human operators reviewing each victim's fingerprint before deciding whether to authorize the next stage. Only targets judged valuable enough receive the third component: a Cobalt Strike beacon, delivered as a JavaScript dropper, that gives the operators durable command-and-control access. The malware disguises its execution as ViberPC.exe, establishes persistence through a registry run key, and hides its infrastructure behind Cloudflare, using .icu and .buzz domains that mask XML configuration traffic as ordinary image responses.

The layered geofencing, human-in-the-loop validation, and staged delivery chain together produce something more consequential than a well-built piece of malware: an operation largely invisible to automated defense. A sandbox environment lacking the correct geography, user agent, and a human operator's approval sees nothing beyond a benign PDF. That is by design. FrostyNeighbor has been active since at least 2016 and, per earlier reporting from FireEye, traces further back to a 2020-documented disinformation campaign aimed at discrediting NATO, aligned with Russian security interests even as the group itself operates from Belarus. Its targeting inside Ukraine remains narrow and deliberate, concentrated on military, defense, and government entities, while its footprint in Poland and Lithuania spreads wider, touching industrial, healthcare, pharmaceutical, and logistics organizations alongside government bodies.
Read in isolation, this is a competent but familiar espionage campaign. Read against the broader regional picture, it is one half of a pattern. ESET has separately documented a Russia-aligned operation expanding westward from Central Asia into Europe this year, and FrostyNeighbor's renewed activity represents what analysts describe as the Belarus-aligned side of the same contested geography, a different actor with a different immediate patron, converging on the same fault line that has defined Eastern European security since 2022. Neither group needs a zero-day to stay effective. What both have is time, discipline, and an adversary environment that continues to reward operators willing to simply keep showing up.