Cybertech Europe 2026-IT Industry Official Media Partner

Belarusian Hackers Attack Opposition and Ukraine with Malicious Code via Excel

Belarusian Hackers Attack Opposition and Ukraine with Malicious Code via Excel Belarusian Hackers Attack Opposition and Ukraine with Malicious Code via Excel

Looking for a Shorter Overview?

Key Moments

Ghostwriter group goals and connections

A Belarusian threat actor linked to Russian interests is attacking opposition and Ukrainian institutions.

Excel macros as an infection technique

Malicious Excel VBA macros are used to download and run Picassoloader via DLL files.

Steganography for malware delivery

Hidden payloads are punched into seemingly harmless JPEG images in attached Excel documents.

Using Libcmd and .NET downloaders

A DLL that runs cmd.exe is loaded into memory via .NET for invisible execution of malicious code.

Ghostwriter group behind new attacks. Opposition activists in Belarus as well as Ukrainian military and government organizations are the targets of a new campaign using Microsoft Excel-malware documents as bait to deliver a new variant of Picassoloader.

The threat cluster has been assessed to be an extension of a long-term campaign mounted by a Belarus-aligned threat actor known as Ghostwriter (alias Moonscape, TA445, UAC-0057 and UNC1151) since 2016. It is known to align with Russian security interests and promote narratives critical of NATO.

In 2024, Ghostwriter has repeatedly used a combination of Excel workbooks with MacroPack obfuscated VBA macros and embedded .NET downloaders

Campaign timeline and activation

“The campaign has been in preparation since July-August 2024 and entered the active phase in November-December 2024,” he said. SentinelOne-the researcher Tom Hegel in a technical report.

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

New discoveries:

  • Malware samples and command-and-control (C2) infrastructure activity suggests that the operation remains active.
  • The attack chain starts with a shared Google Drive-document, hosting a malicious RARE-archives.
Belarus-linked ghostwriter uses MacroPack obfuscated Excel macros to distribute malware

The technology behind the attacks

Excel macros as tools for infection

The RAR file contains a malicious Excel VBA-workbook, which when opened triggers a obfuscated macro. If the user enables macros, a DLLfile to the system, which in turn starts a simplified version of Picassoloader.

Steganography and invisible malware

In the next phase, a Decoy Excel file for the victim, while additional payloads are downloaded in the background. As recently as June 2024, this was used technique to deliver Cobalt Strike-framework.

SentinelOne also identified other armed Excel document who uses Ukraine theme as baitThese documents download malware via steganography, where a seemingly harmless JPG image contains hidden malicious code.

Using Libcmd and .NET downloaders

In some cases, the infected The Excel document to deliver a DLL by name Libcmd, who runs cmd.exe and connects to stdin/stdout. It is loaded directly into memory as a .NET-mounting and running without leaving traces on the disk.

Ghostwriters' continued threats against Ukraine

“In 2024, Ghostwriter repeatedly used a combination of Excel workbooks with MacroPack-obfuscated VBA macros and embedded .NET Downloader, says Hegel.

Despite the fact that Belarus not participating militarily in the war in Ukraine, cyber threat actors linked to the country remain active in cyber espionage operations against Ukrainian targets.

Related Posts

Large-scale wave of phishing attacks targets public officials in Europe

Advanced attacks identified by security researchers IT security firm Check Point Software is warning of an ongoing wave of targeted phishing attacks identified by the company's research team at Check Point

HOLLOWGRAPH turns Microsoft 365 calendars into hidden command and control channels

Group-IB has identified HOLLOWGRAPH, an advanced malware that uses the Microsoft Graph API and Microsoft 365 calendars to hide command and control traffic. By combining…

April threat landscape: Cybercriminals sharpen their tools and FakeUpdates remain the biggest threat

IT security firm Check Point Software has released its April 2025 Threat Landscape Report, which shows that FakeUpdates continue to dominate. At the same time, the researchers reveal how cybercriminals

Questions Answered

What are the targets of the Ghostwriter group's attacks?

Opposition activists in Belarus and Ukrainian military and government organizations.

How is the malicious code spread in this campaign?

Via malicious Excel macros and RAR archives shared through Google Drive.

What techniques are used to hide malicious code in the documents?

Steganography with JPG images and obfuscated VBA macros.

How does malware avoid detection on systems?

By loading DLL files into memory without writing to disk.

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT