The focus of a recent operation is on opposition members in Belarus, as well as military and governmental entities in Ukraine. This operation utilizes Microsoft Excel files containing malware to entice victims into downloading a fresh type of PicassoLoader.
This malicious activity is believed to be an expansion of an ongoing operation conducted by a threat actor associated with Belarus, who is known as Ghostwriter (also identified as Moonscape).
This malicious activity is believed to be an expansion of an ongoing operation conducted by a threat actor associated with Belarus, who is known as Ghostwriter (also identified as Moonscape).
