FrostyNeighbor — APT Profile
FrostyNeighbor is a Belarus-aligned APT group known for conducting influence and disinformation campaigns, particularly targeting Ukraine, Poland, and Lithuania. They have compromised various governmental and private sector entities, including the Polish Anti-Doping Agency, through hack-and-leak operations. The group is believed to collaborate with initial access brokers to exploit high-value targets, utilizing techniques such as zero-day vulnerabilities. Their operations are linked to cyber-enabled disinformation campaigns critical of the North Atlantic Alliance.Also tracked as
Storm-0257, Ghostwriter, UAC-0057, TA445, UNC1151, PUSHCHA, DEV-0257
IntelFusions coverage (1)
- Polish ABW Attributes Sejm DDoS to NoName057(16) as Retaliation for Russia Terrorism Designation, Warns of Escalating Hybrid Cyber Operations 2026-02-16 · Cyber Incidents
Tools & malware
- Cobalt Strike post-exploitation framework
- ConfuserEx .NET obfuscator
- GoPhish phishing framework
- HALFSHELL malware
- HIDDENVALUE malware
- Macropack macro obfuscator
- PicassoDownloader downloader
- PicassoLoader downloader
Vendor research
- FrostyNeighbor: Fresh mischief and digital shenanigans ESET
- Belarus-aligned FrostyNeighbor attacks Ukrainian government, again — ESET Research discovers ESET
- UNC1151 Assessed with High Confidence to have Links to Belarus, Ghostwriter Campaign Aligned with Belarusian Government Interests Mandiant (Google Cloud)
- Ghostwriter | New Campaign Targets Ukrainian Government and Belarusian Opposition SentinelOne