Cybertech Europe 2026-IT Industry Official Media Partner

Belarusian Hackers Attack Opposition and Ukraine with Malicious Code via Excel

Belarusian Hackers Attack Opposition and Ukraine with Malicious Code via Excel Belarusian Hackers Attack Opposition and Ukraine with Malicious Code via Excel

Looking for a Shorter Overview?

Key Moments

Ghostwriter-gruppens mål och kopplingar

En vitrysk hotaktör kopplad till ryska intressen attackerar oppositionella och ukrainska institutioner.

Excel-makron som infektionsteknik

Skadliga Excel VBA-makron används för att ladda ner och köra Picassoloader via DLL-filer.

Steganografi för skadlig kodleverans

Dolda nyttolaster stansas in i till synes ofarliga JPEG-bilder i bifogade Excel-dokument.

Using Libcmd and .NET downloaders

En DLL som kör cmd.exe laddas i minnet via .NET för osynlig exekvering av skadlig kod.

Ghostwriter group behind new attacks. Opposition activists in Belarus as well as Ukrainian military and government organizations are the targets of a new campaign using Microsoft Excel-malware documents as bait to deliver a new variant of Picassoloader.

The threat cluster has been assessed to be an extension of a long-term campaign mounted by a Belarus-aligned threat actor known as Ghostwriter (alias Moonscape, TA445, UAC-0057 and UNC1151) since 2016. It is known to align with Russian security interests and promote narratives critical of NATO.

Under 2024 har Ghostwriter upprepade gånger använt en kombination av Excel-arbetsböcker med MacroPack-obfuskerade VBA-makron och inbäddade .NET-nedladdare

Campaign timeline and activation

“The campaign has been in preparation since July-August 2024 and entered the active phase in November-December 2024,” he said. SentinelOne-the researcher Tom Hegel in a technical report.

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

New discoveries:

  • Malware samples and command-and-control (C2) infrastructure activity suggests that the operation remains active.
  • The attack chain starts with a shared Google Drive-document, hosting a malicious RARE-archives.
Belarus-linked ghostwriter uses MacroPack obfuscated Excel macros to distribute malware

The technology behind the attacks

Excel macros as tools for infection

The RAR file contains a malicious Excel VBA-workbook, which when opened triggers a obfuscated macro. If the user enables macros, a DLLfile to the system, which in turn starts a simplified version of Picassoloader.

Steganography and invisible malware

In the next phase, a Decoy Excel file for the victim, while additional payloads are downloaded in the background. As recently as June 2024, this was used technique to deliver Cobalt Strike-framework.

SentinelOne also identified other armed Excel document who uses Ukraine theme as baitThese documents download malware via steganography, where a seemingly harmless JPG image contains hidden malicious code.

Using Libcmd and .NET downloaders

In some cases, the infected The Excel document to deliver a DLL by name Libcmd, who runs cmd.exe and connects to stdin/stdout. It is loaded directly into memory as a .NET-mounting and running without leaving traces on the disk.

Ghostwriters' continued threats against Ukraine

“In 2024, Ghostwriter repeatedly used a combination of Excel workbooks with MacroPack-obfuscated VBA macros and embedded .NET Downloader, says Hegel.

Despite the fact that Belarus not participating militarily in the war in Ukraine, cyber threat actors linked to the country remain active in cyber espionage operations against Ukrainian targets.

Related Posts

Large-scale wave of phishing attacks targets public officials in Europe

Advanced attacks identified by security researchers IT security firm Check Point Software is warning of an ongoing wave of targeted phishing attacks identified by the company's research team at Check Point

HOLLOWGRAPH turns Microsoft 365 calendars into hidden command and control channels

Group-IB has identified HOLLOWGRAPH, an advanced malware that uses the Microsoft Graph API and Microsoft 365 calendars to hide command and control traffic. By combining…

April threat landscape: Cybercriminals sharpen their tools and FakeUpdates remain the biggest threat

IT security firm Check Point Software has released its April 2025 Threat Landscape Report, which shows that FakeUpdates continue to dominate. At the same time, the researchers reveal how cybercriminals

Questions Answered

Vilka är målen för Ghostwriter-gruppens attacker?

Oppositionsaktivister i Vitryssland och ukrainska militära och regeringsorganisationer.

Hur sprids den skadliga koden i denna kampanj?

Via skadliga Excel-makron och RAR-arkiv delade genom Google Drive.

Vilka tekniker används för att dölja skadlig kod i dokumenten?

Steganografi med JPG-bilder och obfuskerade VBA-makron.

Hur undviker skadlig kod upptäckt på systemen?

Genom att ladda DLL-filer i minnet utan att skriva på disken.

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT