Threat reportAPTTL-2026-0566
Ghostwriter (UAC-0057 / UNC1151) Prometheus-Themed Phishing Chain Drops OYSTERFRESH → OYSTERBLUES → OYSTERSHUCK → Cobalt Strike Against Ukrainian Government
Ghostwriter (UAC-0057 / UNC1151) Prometheus-Themed Phishing (TL-2026-0566), also tracked as Operation Prometheus, is a high-severity advanced persistent threat campaign, first published 2026-05-22. It is attributed to Ghostwriter (Belarus) with high confidence, affects Microsoft Windows (all supported desktop and server SKUs), maps to 22 MITRE ATT&CK techniques (T1005, T1027, T1033), and is covered by 9 detection rules and 23 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 22MITRE ATT&CK
- Actors
- 1Ghostwriter
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 23Indicators of compromise
Key facts for TL-2026-0566
- Threat ID
- TL-2026-0566
- Also known as
- Operation Prometheus, UAC-0057 Prometheus Campaign, OYSTER chain
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- Ghostwriter
- Attribution confidence
- HIGH
- Nation-state nexus
- Belarus
- Motivation
- ESPIONAGE
- Target sectors
- government, defense, education, diplomatic, ngo
- Target regions
- Ukraine, Eastern Europe
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in Ghostwriter (UAC-0057 / UNC1151) Prometheus-Themed Phishing
Malware and tooling: OYSTERBLUES, OYSTERFRESH, OYSTERSHUCK, Cobalt Strike
How Ghostwriter (UAC-0057 / UNC1151) Prometheus-Themed Phishing works
Belarus-aligned APT Ghostwriter (UAC-0057 / UNC1151) is running a phishing campaign against Ukrainian government entities using lures themed around Prometheus, a Ukrainian online-learning platform. Phishing mail sent from compromised mailboxes carries a PDF whose embedded link pulls a ZIP archive containing a JavaScript dropper named OYSTERFRESH; the JS shows a decoy document, plants an obfuscated/encrypted recon payload (OYSTERBLUES) in the Windows Registry, and fetches a decoder/launcher (OYSTERSHUCK). The chain culminates in a Cobalt Strike Beacon for hands-on intrusion, with the campaign disclosed by CERT-UA on 22 May 2026.
Overview
Ghostwriter — tracked as UAC-0057 by CERT-UA and as UNC1151 by Mandiant/Google — is a Belarus-aligned information-operations and intrusion cluster that has targeted Ukrainian, Polish, Lithuanian, German, and Belarusian opposition entities since at least 2017. The spring 2026 campaign disclosed by CERT-UA on 22 May 2026 marks a notable tradecraft shift away from the group's well-documented PicassoLoader / agentTesla / njRAT staging toward a fully JavaScript-anchored, registry-resident loader chain — OYSTERFRESH, OYSTERBLUES, OYSTERSHUCK — that ultimately deploys Cobalt Strike Beacon against Ukrainian government targets.
Initial Access
Delivery is e-mail. Operators send spear-phishing messages from previously-compromised legitimate mailboxes (likely belonging to Ukrainian government or partner organizations), which sidesteps SPF/DKIM/DMARC trust controls and dramatically increases click-through. The lure body and PDF attachment are themed around Prometheus (prometheus.org.ua), a widely used Ukrainian online education platform whose course material and certificate workflows are familiar to government staffers, NGOs and academics. The PDF itself is benign — it carries no exploit — and instead embeds a hyperlink that, when clicked, fetches a ZIP archive from attacker-controlled infrastructure.
Stage 1 — OYSTERFRESH (JavaScript Dropper / Decoy / Registry Writer)
The ZIP unpacks to a single JavaScript (.js) file that executes under wscript.exe by virtue of the default Windows file-association. OYSTERFRESH performs three tasks in sequence:
1. It writes and opens a decoy document — typically a Prometheus course / certificate PDF — to provide visual cover, masking the parent script's continued execution. 2. It carries the second-stage OYSTERBLUES payload as an obfuscated, encrypted blob embedded inside the script itself, and writes that blob to a Windows Registry value under HKCU. Storing the implant in the registry — rather than on disk — is a defense-evasion trick (T1027.011 Fileless Storage; T1112 Modify Registry) that defeats most file-AV signature scanning and survives sandboxes that snapshot only filesystem state. 3. It downloads OYSTERSHUCK from a second-tier C2 over HTTP/HTTPS and launches it. OYSTERSHUCK is responsible for reading OYSTERBLUES out of the registry, decrypting/decoding it, and executing it in memory.
Stage 2 — OYSTERSHUCK (Decoder / Launcher)
OYSTERSHUCK is a small JavaScript or wscript-runnable loader whose only job is to retrieve the registry-stored OYSTERBLUES blob, apply the matching decryption / de-obfuscation routine (string-array indirection, byte-level XOR / arithmetic transforms typical of UAC-0057 PicassoLoader-era code), and invoke the resulting code in-process — most likely via the JScript eval() primitive or via ActiveXObject('WScript.Shell').Run for any spawned native components. The two-file split (writer + decoder) means a defender capturing the initial dropper does not directly recover the payload, and a defender capturing the registry blob does not directly recover the decryption key.
Stage 3 — OYSTERBLUES (Recon / Tasking)
Once decoded and executing, OYSTERBLUES performs host triage:
- Computer name (COMPUTERNAME / hostname) - Current user (USERNAME / whoami) - OS version (Caption / Version from Win32_OperatingSystem) - Last OS boot time (LastBootUpTime from Win32_OperatingSystem) - Running process list (tasklist / Get-Process equivalent via WMI)
The collected data is serialised and shipped to a first-tier C2 by HTTP POST. The server replies with arbitrary JavaScript that OYSTERBLUES then runs through eval() — a tasking primitive that lets the operator stage additional in-memory modules (credential theft, lateral-movement scripts) without re-touching disk or the registry. This eval-driven tasking is the foothold the operator uses to push the final payload.
Stage 4 — Cobalt Strike Beacon
The terminal payload observed in this campaign is Cobalt Strike Beacon, the group's preferred hands-on-keyboard implant going back to the 2023 PicassoLoader→CobaltStrike chains and the 2023 CVE-2023-38831 WinRAR-zero-day variant. Once Beacon is resident the operator pivots to credential dumping (LSASS), Active Directory enumeration (BloodHound / AdFind), and lateral movement to mailboxes, file shares, and domain controllers consistent with prior UAC-0057 objectives: collection of policy / diplomatic / military correspondence and disinformation-supporting leak material.
Attribution
CERT-UA attributes the activity to UAC-0057 (Ghostwriter); Google-Mandiant tracks the same cluster as UNC1151. Public western reporting (Mandiant 2021, SentinelLabs 2022, HarfangLab 2024) and Polish/Lithuanian government statements link the group to the Belarusian regime, with consistent overlap to GRU-aligned information operations supporting Russian strategic objectives. Confidence is HIGH on the actor identification because the malware naming convention, lure ecosystem (Ukrainian gov-adjacent platforms), and target set match prior UAC-0057 operations down to TTPs; confidence is MEDIUM on the precise Belarusian-service operator because public western indictments have not yet named individuals.
Why It Matters
Three previously undocumented malware families in a single chain (OYSTERFRESH / OYSTERBLUES / OYSTERSHUCK) means signatures, YARA, and EDR behavioural rules are sparse to non-existent at the time of disclosure. The chain is also deliberately fileless past the initial ZIP — the only durable artefact on disk after first execution is the original .js (often deleted by the dropper) and the registry value, which most filesystem-only AV will miss. Defenders should treat wscript.exe execution from user-writable paths (Downloads, Temp, AppData) as a high-confidence detection opportunity, in line with CERT-UA's mitigation guidance to restrict wscript.exe for standard users.
MITRE ATT&CK techniques used in TL-2026-0566
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution
Discovery
T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1124 System Time Discovery
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
defense-impairment
Persistence
T1547 Boot or Logon Autostart Execution
Initial Access
Resource Development
T1586 Compromise Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities
Affected products and versions in Ghostwriter (UAC-0057 / UNC1151) Prometheus-Themed Phishing
Remediation for Ghostwriter (UAC-0057 / UNC1151) Prometheus-Themed Phishing
Immediate actions
- Restrict execution of wscript.exe and cscript.exe for standard (non-administrative) user accounts via AppLocker, WDAC, or Software Restriction Policies; CERT-UA explicitly recommends this control.
- Change the default file-handler for .js, .jse, .vbs, .vbe, .wsf, .wsh files from Windows Script Host to a benign editor (notepad.exe) so a double-click cannot launch the dropper.
- Block inbound mail with PDF attachments whose embedded URLs link to ZIP archives at the secure-email-gateway; quarantine for analyst review.
- Sweep HKCU\Software\ and HKCU\Software\Classes\ for large opaque (base64 / hex / binary) REG_SZ or REG_BINARY values written in the last 30 days from user-writable script execution.
- Hunt EDR telemetry for wscript.exe / cscript.exe parent processes that subsequently spawn powershell.exe, rundll32.exe, regsvr32.exe, or perform outbound HTTP POSTs.
Workarounds
- If wscript.exe cannot be globally restricted, at minimum set HKLM\Software\Microsoft\Windows Script Host\Settings\Enabled = 0 for the standard-user OU.
- Configure Microsoft Defender Attack Surface Reduction rule 'Block JavaScript or VBScript from launching downloaded executable content' (GUID D3E037E1-3EB8-44C8-A917-57927947596D) in Block mode.
Longer-term hardening
- Deploy EDR with behavioural detection covering script-host-to-LOLBin transitions and registry-resident payloads (fileless storage, T1027.011).
- Enforce attachment-link rewriting (Safe Links / equivalent) on inbound mail and detonate followed URLs in a sandbox before delivery.
- Egress-filter outbound HTTP/HTTPS from user workstations to allow-listed categories; block category 'unrated' / 'newly-registered domains' from script-host processes.
- Stand up a hunt rule for Cobalt Strike Beacon network traffic (named-pipe lateralisation, default malleable profile JA3/JA3S hashes, beacon-interval analysis) and tune to your environment.
- Mailbox compromise hunting: review sign-in logs and OAuth grants on accounts that have recently sent mail to government recipients — the campaign uses already-compromised mailboxes as the delivery vehicle.
Weaknesses (CWE) in Ghostwriter (UAC-0057 / UNC1151) Prometheus-Themed Phishing
Timeline of Ghostwriter (UAC-0057 / UNC1151) Prometheus-Themed Phishing
- UNC1151 / Ghostwriter activity first observed by Mandiant and FireEye, conducting information operations against NATO eastern flank states (Lithuania, Latvia, Poland).
- Mandiant publicly assesses UNC1151 with high confidence as linked to the Belarusian government and supporting the Ghostwriter information operation.
- UAC-0057 observed exploiting CVE-2023-38831 (WinRAR zero-day) to deliver PicassoLoader and Cobalt Strike, demonstrating capability to weaponise n-day vulnerabilities.
- UAC-0057 campaign documented targeting a leading Ukrainian military educational institution with PicassoLoader and Cobalt Strike.
- HarfangLab publishes 'UAC-0057 keeps applying pressure on Ukraine and Poland,' documenting expanded targeting and AgentTesla / njRAT tradecraft.
- Prometheus-themed phishing campaign begins (spring 2026 per CERT-UA); compromised legitimate mailboxes used as initial delivery vector.
- Threadlinqs Intelligence publishes TL-2026-0566 with full MITRE mapping, IOC set, and detection coverage for the OYSTER chain.
- The Hacker News publishes wider-audience reporting on the campaign, summarising the JS→registry→decoder→Cobalt Strike chain.
- CERT-UA publicly discloses the Prometheus campaign, naming OYSTERFRESH, OYSTERBLUES, and OYSTERSHUCK as previously undocumented malware families and recommending wscript.exe restriction for standard users.
- As of 2026-05-29, this Ghostwriter (UAC-0057/UNC1151) OYSTERFRESH/OYSTERBLUES/OYSTERSHUCK-to-Cobalt-Strike campaign against Ukrainian government is ongoing, disclosed by CERT-UA ~21-22 May 2026 with no takedown reported. No-CVE actor tradecraft, sparse detection coverage, and a long-active Belarus-aligned APT keep it a live threat.
Sources cited for Ghostwriter (UAC-0057 / UNC1151) Prometheus-Themed Phishing
- Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware
- CERT-UA — UAC-0057 advisory portal (Prometheus-themed campaign disclosure)
- UAC-0057 keeps applying pressure on Ukraine and Poland
- Ghostwriter | New Campaign Targets Ukrainian Government and Belarusian Opposition
- PicassoLoader and Cobalt Strike Beacon Detection: UAC-0057 aka GhostWriter Hacking Group Attacks the Ukrainian Leading Military Educational Institution
- CVE-2023-38831 Detection: UAC-0057 Group Exploits a WinRAR Zero-Day to Spread a PicassoLoader Variant and CobaltStrike Beacon via Rabbit Algorithm
- Belarus-linked hackers target Ukrainian orgs with PicassoLoader malware
- AlienVault OTX — Cyberattack of the UAC-0057 (Ghost Writer) group
- MITRE ATT&CK — T1059.007 Command and Scripting Interpreter: JavaScript
- MITRE ATT&CK — T1027.011 Obfuscated Files or Information: Fileless Storage
Detection coverage for TL-2026-0566
As of 2026-05-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0566 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.