CERT-UA Attributes Prometheus-Themed Phishing Run Against Ukrainian Government to Ghostwriter (UAC-0057)

Compromised mailboxes deliver lures impersonating a Ukrainian e-learning platform, with the Belarus-aligned operator tracked as UNC1151 named as the responsible cluster.

ThreatVectr Newsdesk· 2 min read
CERT-UA Attributes Prometheus-Themed Phishing Run Against Ukrainian Government to Ghostwriter (UAC-0057)
Share

The Computer Emergency Response Team of Ukraine (CERT-UA) has attributed a recent phishing campaign against government bodies in the country to the Belarus-aligned activity cluster known as Ghostwriter, also tracked as UAC-0057 and UNC1151. The lures impersonate Prometheus, a widely used Ukrainian online learning platform, and are delivered from previously compromised email accounts belonging to legitimate correspondents.

CERT-UA describes the operation as ongoing. The advisory states that the messages carry attachments engineered to deploy follow-on tooling once a recipient inside a state organisation opens the file. The agency has historically associated UAC-0057 with influence operations and credential theft directed at officials in Ukraine, Poland, Lithuania, and Latvia, with activity intensifying since 2022.

The choice of Prometheus as a pretext is consistent with the group's documented preference for civilian-platform branding that government employees are likely to encounter in routine correspondence. According to CERT-UA, the use of hijacked accounts rather than spoofed senders allows the messages to pass sender-authentication checks and reach inboxes that would otherwise quarantine them.

Ghostwriter has been the subject of attribution work by Mandiant, which since 2020 has linked the UNC1151 designation to operators acting in the interests of the government of Belarus. The cluster is distinguished from purely Russian-aligned groups, though its targeting profile overlaps with operations supporting Moscow's objectives in the region.

One short note. The toolset documented in earlier intrusions has included PicassoLoader and a custom backdoor known as AgentTesla derivatives, though CERT-UA's current bulletin focuses on the delivery chain rather than a full malware family breakdown.

And the operational pattern matters for defenders elsewhere in the European Union. Member-state CERTs operating under the Network and Information Security Directive (NIS2), specifically the cooperation obligations in Article 29, are expected to share indicators bilaterally where cross-border targeting is observed. Ukrainian authorities are not bound by NIS2 but routinely exchange technical artefacts with EU counterparts through CERT-EU.

But the practical recommendation in the advisory is conventional. CERT-UA is urging recipients to verify any unexpected Prometheus-branded correspondence with the sender by a second channel before opening attachments, and to report suspect messages to the agency's incident-response address.

The advisory does not specify a deadline for affected entities to submit telemetry. CERT-UA has indicated that updated indicators of compromise will be published as the campaign is analysed further, and that government bodies should expect a follow-up bulletin in the coming days. Inboxes remain the front door.

© 2026 Threat Vectr