A Ghostwriter Affiliated with Belarus Utilizes Obfuscated Excel Macros from Macropack to Disseminate Malicious Software

The focus of a recent operation is on opposition members in Belarus, as well as military and governmental entities in Ukraine.

The focus of a recent operation is on opposition members in Belarus, as well as military and governmental entities in Ukraine. This operation utilizes Microsoft Excel files containing malware to entice victims into downloading a fresh type of PicassoLoader.
This malicious activity is believed to be an expansion of an ongoing operation conducted by a threat actor associated with Belarus, who is known as Ghostwriter (also identified as Moonscape).

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.