Since early March, Ghostwriter’s use of BitB is only one of a trio of cyber aggressions that TAG
has been tracking with regards to Russia’s invasion of Ukraine.
The use of the war as a lure in phishing and malware campaigns has continued to grow throughout the month, TAG said, with associated cyber-assaults coming in from government-backed actors from China, Iran, North Korea and Russia, as well as from various unattributed groups, according to TAG’s Wednesday post.
Actors “have used various Ukraine war-related themes in an effort to get targets to open malicious emails or click malicious links,” TAG said.
Besides Ghostwriter’s BitB campaigns, TAG has spotted a group it’s calling Curious Gorge that it attributes to China’s PLA SSF conducting campaigns against government and military organizations in Ukraine, Russia, Kazakhstan and Mongolia.
“While this activity largely does not impact Google products, we remain engaged and are providing notifications to victim organizations,” TAG advised.