logo

014

ID: aeadd93e-126f-49f5-a78c-64b31c6924f9

STIX ID: report--aeadd93e-126f-49f5-a78c-64b31c6924f9

Threat Score

85/100

Uploaded: 2026-05-14

Created by: Thesis Research

TLP:GREEN
...
...
Opposition activists in Belarus and Ukrainian military and government organizations were targeted by a Ghostwriter (UNC1151) campaign that used weaponized Microsoft Excel documents containing obfuscated VBA macros and steganographic payload delivery to install a new PicassoLoader variant, Cobalt Strike, and a LibCMD DLL; the operation was active from mid-2024 into late 2024 and exhibited ongoing C2 activity.