Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GhostShell Malware Targets Ukrainian Drones Using mTLS and Telegram

GhostShell Malware Targets Ukrainian Drones Using mTLS and Telegram

Posted on June 24, 2026 By CWS

A new cyber threat, dubbed GhostShell, has been identified as targeting Ukraine’s drone technology and its wider defense supply chain. The sophisticated malware utilizes mutual TLS (mTLS) and Telegram-based dead-drop methods to maintain a stealthy presence within affected networks.

Advanced Techniques in Cyber Attacks

GhostShell employs multiple advanced techniques, including a mutual TLS implant and a Telegram dead-drop resolver, to ensure stealth and persistence. These methods indicate a deliberate strategy by the threat actor, who has been active since at least February 2026, to compromise entities within the Ukrainian UAV sector.

The malware is delivered through an archive named Besomar_documentation.rar, which exploits vulnerabilities CVE-2025-8088 and CVE-2025-6218. Opening this file silently installs a malicious script in the Windows Startup folder, ensuring the malware’s execution with each system boot.

Targeting the Drone Ecosystem

According to Synaptic Security researchers, who detailed their findings in a report shared with Cyber Security News, GhostShell’s decoy documents are crafted to resemble those of Besomar, a Ukrainian drone manufacturer. These documents cover a wide range of targets, from military units to procurement staff, suggesting a broad interest in the entire drone supply chain.

The malware delivers three distinct payloads after execution. One establishes a persistent implant, another utilizes a Telegram channel to acquire the attacker’s server address, and a third tunnels data through an encrypted proxy. This multifaceted approach complicates efforts to completely disrupt the attacker’s access.

Implications for Defense and Security

The GhostShell attack sequence begins with the malicious RAR archive, exploiting its vulnerabilities to plant a startup script. This script then facilitates the download of three payloads from a domain registered in early 2026. Diversifying registrars and hosting providers minimizes the risk of a complete shutdown.

Organizations connected to Ukraine’s defense industry must exercise caution with unsolicited compressed files, particularly those referencing drone equipment. Blocking newly registered domains and monitoring for specific mTLS client certificates can help mitigate exposure to similar threats.

The emergence of GhostShell underscores the evolving nature of cyber threats targeting critical defense infrastructure. As attackers employ increasingly sophisticated methods, continuous adaptation in defense strategies is crucial to safeguarding sensitive operational technologies.

Cyber Security News Tags:cyber attack, cyber threat, Cybersecurity, defense sector, drone technology, GhostShell, Malware, mTLS, Telegram, Ukrainian drones

Post navigation

Previous Post: AIVEX: A New Model to Mitigate Supply Chain Risks
Next Post: Microsoft and Partners Dismantle Amadey and StealC Malware

Related Posts

Microsoft Defender Boosts Threat Response with New Script Library Microsoft Defender Boosts Threat Response with New Script Library Cyber Security News
Halo Security Honored with 2025 MSP Today Product of the Year Award Halo Security Honored with 2025 MSP Today Product of the Year Award Cyber Security News
Microsoft Zero Day Quest Hacking Contest Microsoft Zero Day Quest Hacking Contest Cyber Security News
First-Ever Malicious MCP Server Found in the Wild Steals Emails via AI Agents First-Ever Malicious MCP Server Found in the Wild Steals Emails via AI Agents Cyber Security News
Threat Actors Weaponizing .hwp Files to Deliver RokRAT Malware Threat Actors Weaponizing .hwp Files to Deliver RokRAT Malware Cyber Security News
Claude AI Flaws Risk Data Theft and Unsafe Redirects Claude AI Flaws Risk Data Theft and Unsafe Redirects Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russia’s Use of Cellebrite to Access Activist’s iPhone
  • Microsoft Secure Boot Certificate Expiry Impacts Billions
  • Curl’s 25-Year Security Flaw Patched in Major Update
  • Popular Chrome Ad Blocker Raises Security Concerns
  • Malicious npm Packages Compromise Developer Credentials

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russia’s Use of Cellebrite to Access Activist’s iPhone
  • Microsoft Secure Boot Certificate Expiry Impacts Billions
  • Curl’s 25-Year Security Flaw Patched in Major Update
  • Popular Chrome Ad Blocker Raises Security Concerns
  • Malicious npm Packages Compromise Developer Credentials

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark