Home · Briefs · CTI Weekly Summary — 2026-W21 (Mon 18 – Sun 24, 2026)
FrostyNeighbor / Ghostwriter (UNC1151, Belarus state-aligned) — March–May 2026 campaign confirmed [SINGLE-SOURCE: ESET]
From CTI Weekly Summary — 2026-W21 (Mon 18 – Sun 24, 2026) · published 2026-05-18
ESET's May 2026 analysis documented an ongoing campaign targeting Ukrainian government organisations with spear-phishing — PDF lures impersonating Ukrtelecom delivering PicassoLoader and Cobalt Strike as initial foothold. The campaign overlaps with the historical Ghostwriter disinformation operations against Ukrainian and EU audiences. Swiss and EU government and media entities with Ukraine-related policy exposure should treat FrostyNeighbor as an active threat. No developments beyond the ESET disclosure surfaced in the W21 research window.