New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector
A new cyberattack campaign has been discovered targeting Ukraine’s drone sector, including military units, supply chains, and volunteer groups. Security researchers at Synaptic Systems recently analysed the activity and named the new group behind it GhostShell and the tracking label MB-0009. Reportedly, it has been active since at least February 2026.
How the Attack Works
GhostShell uses a trick called a decoy document to trap its targets. They sent a malicious compressed folder named Besomar_documentation.rar. When opened, this archive secretly copies a hidden script into the Windows Startup folder. This step allows the malware to run every time the computer turns on.
At the same time, the victim sees harmless-looking PDF documents. These docs are written in Ukrainian and pretend to be from Besomar, a real Ukrainian company that makes defense drones. These fake documents include titles about drone configurations and charging stations to make the trap look...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE