Belarus-Linked Ghostwriter Uses Macropack-Obfuscated Excel Macros to Deploy Malware
A new effort uses Microsoft Excel documents infected with malware as enticements to spread a new version of PicassoLoader, targeting Ukrainian military and government institutions as well as opposition activists in Belarus.
According to assessments, the threat cluster is an extension of a campaign that has been ongoing since 2016 by a threat actor with ties to Belarus known as Ghostwriter (also known as Moonscape, TA445, UAC-0057, and UNC1151). It has a reputation for supporting storylines that are critical of NATO and supporting Russian security interests.
under a technical report sent to The Hacker News, SentinelOne researcher Tom Hegel stated that the campaign had been under planning read more about Belarus-Linked Ghostwriter Uses Macropack-Obfuscated Excel Macros to Deploy Malwa...

