CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

FrostyNeighbor March–May 2026 campaign

campaign · campaign:frostyneighbor-2026-05-campaign single-sourcesingle-source-national-cert

FrostyNeighbor (Ghostwriter / UNC1151) March–May 2026 campaign against Poland, Lithuania and Ukraine.

Aliases: Ghostwriter, UNC1151

Coverage
4
first 2026-05-08 → last 2026-07-09
Latest activity
2026-07-09
CERT-PL: Ghostwriter/UNC1151 now phishes Gmail with a live 2FA-relay panel that defeats TOTP and SMS
Peak priority
high
2 high · 2 notable
Targets
public-sector
sectors: public-sector, defense, education · regions: europe, switzerland, dach
Sources cited
12
7 hosts
2026-05-084 appearances2026-07-09

Action items (2)

Do-now tasks recorded on the entries about FrostyNeighbor March–May 2026 campaign, newest first. Check the date before acting on an older one.

Defender insights

What each entry about FrostyNeighbor March–May 2026 campaign tells a defender to do, newest first.

2026-07-09HIGHCERT-PL: Ghostwriter/UNC1151 now phishes Gmail with a live 2FA-relay panel that defeats TOTP and SMS

Story timeline

  1. 2026-07-09CERT Polska: UNC1151/Ghostwriter shifts to Gmail with real-time 2FA-relay phishing against officials and public administration
    active-threatsCERT-PL: Ghostwriter/UNC1151 now phishes Gmail with a live 2FA-relay panel that defeats TOTP and SMS
  2. 2026-05-23Ghostwriter / UAC-0057 / FrostyNeighbor, CERT-UA documents new OYSTERFRESH → OYSTERBLUES → OYSTERSHUCK implant chain via Prometheus learning-platform lures
    active-threats
  3. 2026-05-15FrostyNeighbor / Ghostwriter (UNC1151, Belarus state-aligned): ESET documents March–May 2026 campaign targeting Polish, Lithuanian, and Ukrainian government and industrial sectors
    active-threatsFrostyNeighbor / Ghostwriter (UNC1151, Belarus state-aligned): ESET documents March–May 2026 campaign targeting Polish, Lithuanian, and Ukrainian government
  4. 2026-05-08Pro-Russian hacktivists modify OT pump settings at five Polish water treatment facilities
    active-threats
ATT&CK techniques (10 across 7 tactics)

10 techniques observed across 3 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessPhishing · Phishing: Spearphishing Attachment · Phishing: Spearphishing Link
  • ExecutionCommand and Scripting Interpreter · Command and Scripting Interpreter: JavaScript
  • PersistenceBoot or Logon Autostart Execution: Registry Run Keys / Startup Folder
  • Privilege EscalationBoot or Logon Autostart Execution: Registry Run Keys / Startup Folder
  • StealthObfuscated Files or Information
  • DiscoverySystem Information Discovery
  • Command and ControlIngress Tool Transfer · Remote Access Tools

Initial Access TA0001

T1566Phishing×1

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-05-15/frostyneighbor-ghostwriter-unc1151-belarus-state-aligned-ese · ATT&CK page ↗

T1566.001Phishing: Spearphishing Attachment×1

Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

Evidence: 2026-05-15/frostyneighbor-ghostwriter-unc1151-belarus-state-aligned-ese · ATT&CK page ↗

T1566.002Phishing: Spearphishing Link×1

Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

Evidence: 2026-07-09/unc1151-ghostwriter-gmail-realtime-2fa-phishing · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-05-15/frostyneighbor-ghostwriter-unc1151-belarus-state-aligned-ese · ATT&CK page ↗

T1059.007Command and Scripting Interpreter: JavaScript×2

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-05-23/ghostwriter-uac-0057-frostyneighbor-cert-ua-documents-new-oy · 2026-05-15/frostyneighbor-ghostwriter-unc1151-belarus-state-aligned-ese · ATT&CK page ↗

Persistence TA0003

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-05-23/ghostwriter-uac-0057-frostyneighbor-cert-ua-documents-new-oy · ATT&CK page ↗

Privilege Escalation TA0004

T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.

Evidence: 2026-05-23/ghostwriter-uac-0057-frostyneighbor-cert-ua-documents-new-oy · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×2

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-05-23/ghostwriter-uac-0057-frostyneighbor-cert-ua-documents-new-oy · 2026-05-15/frostyneighbor-ghostwriter-unc1151-belarus-state-aligned-ese · ATT&CK page ↗

Discovery TA0007

T1082System Information Discovery×1

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.

Evidence: 2026-05-15/frostyneighbor-ghostwriter-unc1151-belarus-state-aligned-ese · ATT&CK page ↗

Command and Control TA0011

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-05-15/frostyneighbor-ghostwriter-unc1151-belarus-state-aligned-ese · ATT&CK page ↗

T1219Remote Access Tools×1

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-05-23/ghostwriter-uac-0057-frostyneighbor-cert-ua-documents-new-oy · ATT&CK page ↗

Entries about FrostyNeighbor March–May 2026 campaign (4)

2026-07-09 · view entry permalink →

HIGHNATOA2

CERT Polska: UNC1151/Ghostwriter shifts to Gmail with real-time 2FA-relay phishing against officials and public administration

CERT Polska (NASK) reports that UNC1151/Ghostwriter, the Belarus-linked cluster that for years phished Polish-provider webmail (Onet, WP, Interia), has since March 2026 shifted at high, near-daily intensity to Gmail accounts, with new phishing domains appearing almost daily (CERT Polska, 2026-07-08). The lure imitates a Gmail security/administrator notice ("suspicious activity", "account may be blocked") written in error-free Polish and sent from purpose-created Gmail accounts or compromised mailboxes with a spoofed display name, frequently via BCC to obscure the target list. Targeting is broad (political and public-life figures, senior officials, researchers, journalists, public-administration and law-enforcement staff, and their family and social contacts) with some campaigns narrowed to specific professional groups such as translators and court experts.

The core technical escalation over prior campaigns is a real-time second-factor relay: after harvesting the password, the fake login panel displays a second form requesting the TOTP/SMS code, which the operators feed into an automated login against the real account, defeating both app-based (Google Authenticator) and SMS-based factors (CERT Polska, 2026-07-08). Infrastructure mixes dedicated phishing domains on .icu/.digital/.top TLDs with abuse of *.netlify.app subdomains, plus fake panels planted on compromised Polish websites whose main pages are left untouched to avoid tipping off the site owner. The initial lure maps to T1566.002 Phishing: Spearphishing Link; the live-relay capture is best described qualitatively (CERT Polska does not name specific AitM tooling).

Since March 2026, however, the group has been running phishing campaigns targeting Gmail users. These campaigns are carried out with high intensity, mainly on weekdays. Notably, they enable the theft of two-factor authentication (2FA) credentials.

If a second factor is required, the phishing page displays an additional form requesting the code. This allows attackers to capture both SMS-based codes and those generated by applications such as Google Authenticator.

CERT Polska
threat09 Jul 04:32Zsingle-source · national CERTOpen finding →

2026-05-23 · view entry permalink →

NOTABLE

Ghostwriter / UAC-0057 / FrostyNeighbor, CERT-UA documents new OYSTERFRESH → OYSTERBLUES → OYSTERSHUCK implant chain via Prometheus learning-platform lures

UPDATE (originally covered weekly 2026-W21): CERT-UA published a bulletin (surfaced 2026-05-22) on a spring-2026 phishing campaign by Ghostwriter (a.k.a. UAC-0057, UNC1151, FrostyNeighbor) targeting Ukrainian government entities through lures themed on the Prometheus online-learning platform (The Hacker News, 2026-05-22 · SC World, 2026-05-22). The material delta from this week's weekly long-running coverage of FrostyNeighbor / Ghostwriter activity is a new three-stage implant trio distinct from the prior PicassoLoader toolset.

Chain: phishing email from a compromised account → PDF attachment with a link to a ZIP archive → ZIP carrying a JavaScript file (OYSTERFRESH). OYSTERFRESH renders a decoy document as cover while writing an obfuscated, RC4-encrypted OYSTERBLUES payload to the Windows Registry and launching OYSTERSHUCK. OYSTERSHUCK decodes OYSTERBLUES (executed via JavaScript) which then collects computer name, user account, OS version, last boot time and running process list, exfiltrates via HTTP POST to C2, and executes dynamically received JavaScript via eval(). The final payload is assessed as Cobalt Strike. (MITRE ATT&CK overlay added by this brief, not by the CERT-UA narrative as carried by The Hacker News: T1027 Obfuscated Files/Information on the OYSTERFRESH stage, T1547.001 Registry Run Keys on the OYSTERBLUES persistence, T1059.007 JavaScript on OYSTERSHUCK execution, T1219 Remote Access Software on the Cobalt Strike final.)

Defender vantage: CERT-UA's own recommendation is to block wscript.exe execution for standard user accounts, a high-yield control because the OYSTER trio relies on script-host execution from user context. EDR signal: wscript.exe spawning powershell.exe or a base64-encoded command; registry monitoring for new HKCU\Software Run-key values containing binary blobs or script paths; hunt for Cobalt Strike beacon signatures in HTTP POST egress to non-corporate domains. The EU/CH relevance is direct: Ghostwriter historically targets Belgium, Germany, Poland, Lithuania, Latvia and other NATO members alongside Ukraine, and the OYSTER implant chain is a toolset upgrade defenders should expect to see surfaced in EU government tenants and Eastern-Europe-focused think tanks.

threat23 May 05:00Zmulti-sourceOpen finding →

2026-05-15 · view entry permalink →

NOTABLE

FrostyNeighbor / Ghostwriter (UNC1151, Belarus state-aligned): ESET documents March–May 2026 campaign targeting Polish, Lithuanian, and Ukrainian government and industrial sectors

ESET published a new technical report on 2026-05-14 documenting fresh operational activity from FrostyNeighbor (a cluster ESET and Mandiant track as Ghostwriter / UNC1151 / UAC-0057, assessed as apparently Belarus state-aligned) against Polish, Lithuanian, and Ukrainian government and industrial organisations across a March–May 2026 wave (ESET WeLiveSecurity, 2026-05-14). The Ukraine strand distributes RAR archives via spear-phishing PDFs impersonating Ukrtelecom; the archives drop a JavaScript downloader (a PicassoLoader variant) that fingerprints the victim environment (username, process list, OS version) and beacons every 10 minutes to operator infrastructure. A server-side geofencing check delivers a benign decoy to IPs outside Ukraine, making emulation from a non-Ukrainian network appear clean. Polish and Lithuanian targeting covers industrial/manufacturing, healthcare and pharmaceuticals, logistics, and government organisations; ESET documents victimology spanning both NATO member states in the same campaign wave. Once operators manually approve a victim, a Cobalt Strike Beacon payload is staged, indicating deliberate victim-vetting prior to full post-compromise operations. MITRE ATT&CK: T1566.001 (Spearphishing Attachment), T1027 (Obfuscated Files), T1059.007 (JavaScript), T1082 (System Information Discovery, victim-vetting step), T1105 (Ingress Tool Transfer, Cobalt Strike staging). Detection: alert on JavaScript execution from browser/document-viewer parent-process trees, followed by 10-minute periodic outbound HTTP(S) beacons to a new destination; test detections with Ukrainian-egress routing to bypass the geofencing blind spot.

threat15 May 05:00Zmulti-sourceOpen finding →

Earlier coverage (1)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats4

Source distribution

  • attack.mitre.org5 (42%)
  • thehackernews.com2 (17%)
  • abw.gov.pl1 (8%)
  • cert.pl1 (8%)
  • cisa.gov1 (8%)
  • scworld.com1 (8%)
  • welivesecurity.com1 (8%)