FrostyNeighbor: Fresh Mischief and Digital Shenanigans
ESET Research, Thursday, May 14th, 2026
ESET researchers reveal new FrostyNeighbor cyberespionage activities targeting Ukrainian government organizations with updated toolsets.
ESET researchers have uncovered newly discovered activities attributed to FrostyNeighbor, a long-running cyberespionage group allegedly operating from Belarus that targets governmental and military organizations in Eastern Europe, particularly Ukraine.
The report documents new activity beginning in March 2026, showing the group's continued evolution of tactics, techniques, and procedures, including a new compromise chain using JavaScript-based PicassoLoader to deliver Cobalt Strike payloads.
FrostyNeighbor employs server-side validation to verify victims before delivering final payloads and uses a variety of lure documents, spearphishing campaigns, and legitimate services like Slack for payload delivery. The group has demonstrated sophisticated evasion techniques, including dynamic CAPTCHAs and anti-analysis methods, while targeting a wide range of sectors across Eastern Europe including military, defense, industrial, healthcare, and logistics.