# Ghostwriter (UAC-0057 / UNC1151) Prometheus-Themed Phishing Chain Drops OYSTERFRESH → OYSTERBLUES → OYSTERSHUCK → Cobalt Strike Against Ukrainian Government

> Belarus-aligned APT Ghostwriter (UAC-0057 / UNC1151) is running a phishing campaign against Ukrainian government entities using lures themed around Prometheus, a Ukrainian online-learning platform. Phishing mail sent from compromised mailboxes carries a PDF whose embedded link pulls a ZIP archive containing a JavaScript dropper named OYSTERFRESH; the JS shows a decoy document, plants an obfuscated/encrypted recon payload (OYSTERBLUES) in the Windows Registry, and fetches a decoder/launcher (OYSTERSHUCK). The chain culminates in a Cobalt Strike Beacon for hands-on intrusion, with the campaign disclosed by CERT-UA on 22 May 2026.

- **Published:** 2026-05-22T12:00:00Z
- **Last reviewed:** 2026-05-22T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0566
- **ID:** TL-2026-0566
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** Ghostwriter (Belarus)
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Overview

Ghostwriter — tracked as UAC-0057 by CERT-UA and as UNC1151 by Mandiant/Google — is a Belarus-aligned information-operations and intrusion cluster that has targeted Ukrainian, Polish, Lithuanian, German, and Belarusian opposition entities since at least 2017. The spring 2026 campaign disclosed by CERT-UA on 22 May 2026 marks a notable tradecraft shift away from the group's well-documented PicassoLoader / agentTesla / njRAT staging toward a fully JavaScript-anchored, registry-resident loader chain — OYSTERFRESH, OYSTERBLUES, OYSTERSHUCK — that ultimately deploys Cobalt Strike Beacon against Ukrainian government targets.

Initial Access

Delivery is e-mail. Operators send spear-phishing messages from previously-compromised legitimate mailboxes (likely belonging to Ukrainian government or partner organizations), which sidesteps SPF/DKIM/DMARC trust controls and dramatically increases click-through. The lure body and PDF attachment are themed around Prometheus (prometheus.org.ua), a widely used Ukrainian online education platform whose course material and certificate workflows are familiar to government staffers, NGOs and academics. The PDF itself is benign — it carries no exploit — and instead embeds a hyperlink that, when clicked, fetches a ZIP archive from attacker-controlled infrastructure.

Stage 1 — OYSTERFRESH (JavaScript Dropper / Decoy / Registry Writer)

The ZIP unpacks to a single JavaScript (.js) file that executes under wscript.exe by virtue of the default Windows file-association. OYSTERFRESH performs three tasks in sequence:

1. It writes and opens a decoy document — typically a Prometheus course / certificate PDF — to provide visual cover, masking the parent script's continued execution.
2. It carries the second-stage OYSTERBLUES payload as an obfuscated, encrypted blob embedded inside the script itself, and writes that blob to a Windows Registry value under HKCU. Storing the implant in the registry — rather than on disk — is a defense-evasion trick (T1027.011 Fileless Storage; T1112 Modify Registry) that defeats most file-AV signature scanning and survives sandboxes that snapshot only filesystem state.
3. It downloads OYSTERSHUCK from a second-tier C2 over HTTP/HTTPS and launches it. OYSTERSHUCK is responsible for reading OYSTERBLUES out of the registry, decrypting/decoding it, and executing it in memory.

Stage 2 — OYSTERSHUCK (Decoder / Launcher)

OYSTERSHUCK is a small JavaScript or wscript-runnable loader whose only job is to retrieve the registry-stored OYSTERBLUES blob, apply the matching decryption / de-obfuscation routine (string-array indirection, byte-level XOR / arithmetic transforms typical of UAC-0057 PicassoLoader-era code), and invoke the resulting code in-process — most likely via the JScript eval() primitive or via ActiveXObject('WScript.Shell').Run for any spawned native components. The two-file split (writer + decoder) means a defender capturing the initial dropper does not directly recover the payload, and a defender capturing the registry blob does not directly recover the decryption key.

Stage 3 — OYSTERBLUES (Recon / Tasking)

Once decoded and executing, OYSTERBLUES performs host triage:

- Computer name (COMPUTERNAME / hostname)
- Current user (USERNAME / whoami)
- OS version (Caption / Version from Win32_OperatingSystem)
- Last OS boot time (LastBootUpTime from Win32_OperatingSystem)
- Running process list (tasklist / Get-Process equivalent via WMI)

The collected data is serialised and shipped to a first-tier C2 by HTTP POST. The server replies with arbitrary JavaScript that OYSTERBLUES then runs through eval() — a tasking primitive that lets the operator stage additional in-memory modules (credential theft, lateral-movement scripts) without re-touching disk or the registry. This eval-driven tasking is the foothold the operator uses to push the final payload.

Stage 4 — Cobalt Strike Beacon

The terminal payload observed in this campaign is Cobalt Strike Beacon, the group's preferred hands-on-keyboard implant going back to the 2023 PicassoLoader→CobaltStrike chains and the 2023 CVE-2023-38831 WinRAR-zero-day variant. Once Beacon is resident the operator pivots to credential dumping (LSASS), Active Directory enumeration (BloodHound / AdFind), and lateral movement to mailboxes, file shares, and domain controllers consistent with prior UAC-0057 objectives: collection of policy / diplomatic / military correspondence and disinformation-supporting leak material.

Attribution

CERT-UA attributes the activity to UAC-0057 (Ghostwriter); Google-Mandiant tracks the same cluster as UNC1151. Public western reporting (Mandiant 2021, SentinelLabs 2022, HarfangLab 2024) and Polish/Lithuanian government statements link the group to the Belarusian regime, with consistent overlap to GRU-aligned information operations supporting Russian strategic objectives. Confidence is HIGH on the actor identification because the malware naming convention, lure ecosystem (Ukrainian gov-adjacent platforms), and target set match prior UAC-0057 operations down to TTPs; confidence is MEDIUM on the precise Belarusian-service operator because public western indictments have not yet named individuals.

Why It Matters

Three previously undocumented malware families in a single chain (OYSTERFRESH / OYSTERBLUES / OYSTERSHUCK) means signatures, YARA, and EDR behavioural rules are sparse to non-existent at the time of disclosure. The chain is also deliberately fileless past the initial ZIP — the only durable artefact on disk after first execution is the original .js (often deleted by the dropper) and the registry value, which most filesystem-only AV will miss. Defenders should treat wscript.exe execution from user-writable paths (Downloads, Temp, AppData) as a high-confidence detection opportunity, in line with CERT-UA's mitigation guidance to restrict wscript.exe for standard users.

## MITRE ATT&CK

- T1586 Compromise Accounts
- T1587 Develop Capabilities
- T1588 Obtain Capabilities
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1047 Windows Management Instrumentation
- T1547 Boot or Logon Autostart Execution
- T1027 Obfuscated Files or Information
- T1112 Modify Registry
- T1218 System Binary Proxy Execution
- T1036 Masquerading
- T1140 Deobfuscate/Decode Files or Information
- T1082 System Information Discovery
- T1033 System Owner/User Discovery
- T1057 Process Discovery
- T1124 System Time Discovery
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1573 Encrypted Channel
- T1041 Exfiltration Over C2 Channel

## Sources

- [Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware](https://thehackernews.com/2026/05/ghostwriter-targets-ukraine-government.html)
- [CERT-UA — UAC-0057 advisory portal (Prometheus-themed campaign disclosure)](https://cert.gov.ua/search/UAC-0057)
- [UAC-0057 keeps applying pressure on Ukraine and Poland](https://harfanglab.io/insidethelab/uac-0057-pressure-ukraine-poland/)
- [Ghostwriter | New Campaign Targets Ukrainian Government and Belarusian Opposition](https://www.sentinelone.com/labs/ghostwriter-new-campaign-targets-ukrainian-government-and-belarusian-opposition/)
- [PicassoLoader and Cobalt Strike Beacon Detection: UAC-0057 aka GhostWriter Hacking Group Attacks the Ukrainian Leading Military Educational Institution](https://socprime.com/blog/picassoloader-and-cobalt-strike-beacon-detection-uac-0057-aka-ghostwriter-hacking-group-attacks-the-ukrainian-leading-military-educational-institution/)
- [CVE-2023-38831 Detection: UAC-0057 Group Exploits a WinRAR Zero-Day to Spread a PicassoLoader Variant and CobaltStrike Beacon via Rabbit Algorithm](https://socprime.com/blog/cve-2023-38831-detection-uac-0057-group-exploits-a-winrar-zero-day-to-spread-a-picassoloader-variant-and-cobaltstrike-beacon-via-rabbit-algorithm/)
- [Belarus-linked hackers target Ukrainian orgs with PicassoLoader malware](https://therecord.media/belarus-ukraine-picasso-malware-ghostwriter)
- [AlienVault OTX — Cyberattack of the UAC-0057 (Ghost Writer) group](https://otx.alienvault.com/pulse/64994f4777527e0d9293dacd)
- [MITRE ATT&CK — T1059.007 Command and Scripting Interpreter: JavaScript](https://attack.mitre.org/techniques/T1059/007/)
- [MITRE ATT&CK — T1027.011 Obfuscated Files or Information: Fileless Storage](https://attack.mitre.org/techniques/T1027/011/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0566
