Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GhostShell Malware Targets Ukrainian Drones Using mTLS and Telegram

GhostShell Malware Targets Ukrainian Drones Using mTLS and Telegram

Posted on June 24, 2026 By CWS

A new cyber threat, dubbed GhostShell, has been identified as targeting Ukraine’s drone technology and its wider defense supply chain. The sophisticated malware utilizes mutual TLS (mTLS) and Telegram-based dead-drop methods to maintain a stealthy presence within affected networks.

Advanced Techniques in Cyber Attacks

GhostShell employs multiple advanced techniques, including a mutual TLS implant and a Telegram dead-drop resolver, to ensure stealth and persistence. These methods indicate a deliberate strategy by the threat actor, who has been active since at least February 2026, to compromise entities within the Ukrainian UAV sector.

The malware is delivered through an archive named Besomar_documentation.rar, which exploits vulnerabilities CVE-2025-8088 and CVE-2025-6218. Opening this file silently installs a malicious script in the Windows Startup folder, ensuring the malware’s execution with each system boot.

Targeting the Drone Ecosystem

According to Synaptic Security researchers, who detailed their findings in a report shared with Cyber Security News, GhostShell’s decoy documents are crafted to resemble those of Besomar, a Ukrainian drone manufacturer. These documents cover a wide range of targets, from military units to procurement staff, suggesting a broad interest in the entire drone supply chain.

The malware delivers three distinct payloads after execution. One establishes a persistent implant, another utilizes a Telegram channel to acquire the attacker’s server address, and a third tunnels data through an encrypted proxy. This multifaceted approach complicates efforts to completely disrupt the attacker’s access.

Implications for Defense and Security

The GhostShell attack sequence begins with the malicious RAR archive, exploiting its vulnerabilities to plant a startup script. This script then facilitates the download of three payloads from a domain registered in early 2026. Diversifying registrars and hosting providers minimizes the risk of a complete shutdown.

Organizations connected to Ukraine’s defense industry must exercise caution with unsolicited compressed files, particularly those referencing drone equipment. Blocking newly registered domains and monitoring for specific mTLS client certificates can help mitigate exposure to similar threats.

The emergence of GhostShell underscores the evolving nature of cyber threats targeting critical defense infrastructure. As attackers employ increasingly sophisticated methods, continuous adaptation in defense strategies is crucial to safeguarding sensitive operational technologies.

Cyber Security News Tags:cyber attack, cyber threat, Cybersecurity, defense sector, drone technology, GhostShell, Malware, mTLS, Telegram, Ukrainian drones

Post navigation

Previous Post: AIVEX: A New Model to Mitigate Supply Chain Risks
Next Post: Microsoft and Partners Dismantle Amadey and StealC Malware

Related Posts

Critical Zoom Vulnerability on Windows Requires Urgent Update Critical Zoom Vulnerability on Windows Requires Urgent Update Cyber Security News
Critical WordPress RCE Vulnerability Discovered by AI Critical WordPress RCE Vulnerability Discovered by AI Cyber Security News
CypherLoc Kit Traps Users with Fake Microsoft Support Calls CypherLoc Kit Traps Users with Fake Microsoft Support Calls Cyber Security News
CISA Highlights Apache ActiveMQ Security Flaw Threat CISA Highlights Apache ActiveMQ Security Flaw Threat Cyber Security News
North Korean Hackers Make History with  Billion Crypto Heist in 2025 North Korean Hackers Make History with $2 Billion Crypto Heist in 2025 Cyber Security News
Chrome Patches High-severity Implementation Vulnerability in V8 JavaScript engine Chrome Patches High-severity Implementation Vulnerability in V8 JavaScript engine Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cloudflare Secures Containers After Disk Data Exposure
  • Bitget Hot Wallet Breach Exposes $351.6 Million
  • Innovative Method Challenges RSA Security Without Factoring
  • AI-Induced Hacks Challenge Legal Frameworks
  • SCOUTz Launches Beta for MSPs with New Intelligence Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cloudflare Secures Containers After Disk Data Exposure
  • Bitget Hot Wallet Breach Exposes $351.6 Million
  • Innovative Method Challenges RSA Security Without Factoring
  • AI-Induced Hacks Challenge Legal Frameworks
  • SCOUTz Launches Beta for MSPs with New Intelligence Platform

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark