PicassoLoader is a Windows payload downloader associated with the Belarus-linked cyberespionage actor Ghostwriter, also tracked as FrostyNeighbor, UAC-0057, and UNC1151. Implementations have been observed in .NET, PowerShell, JavaScript, and C++. It stages additional malware, notably Cobalt Strike Beacon, and has been used in operations targeting Ukrainian government, military, and critical energy-sector organizations.
Delivery mechanisms include malicious macro-enabled Microsoft Office documents, spearphishing emails carrying PDF lures that link to malicious archives, and exploitation of the WinRAR vulnerability CVE-2023-38831. Infection chains commonly display legitimate-looking decoy documents while malicious scripts execute in the background. Payloads can be disguised as images or concealed within web-associated files; an observed JavaScript implementation extracted and decrypted a .NET payload embedded in an SVG image using the Rabbit algorithm.
JavaScript variants profile compromised systems by collecting usernames, computer names, operating-system versions, boot times, and running processes. In a campaign active since March 2026, PicassoLoader transmitted host profiles through HTTP POST requests every ten minutes and executed JavaScript returned by its command-and-control server. Operators selectively deployed a subsequent Cobalt Strike dropper after reviewing victim information. The associated delivery infrastructure used geographic filtering to serve malicious archives to Ukrainian IP addresses while returning benign documents to other visitors, limiting exposure to automated analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-38831, the WinRAR zero-day remote code execution vulnerability, has been exploited in the wild to distribute several malware families.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Multiple VBS and Bat. files are created and launched to deploy the next-stage of malware named PicassoLoader malware to target the Ukrainian critical energy sector.
Analysis of Dwnldr.dll shows that it is a DLL file with a .NET assembly embedded inside. The file is protected with ConfuserEx... The DLL file hosts a payload that appears to be a simplified variant of PicassoDownloader, a malware family also linked to Ghostwriter activity... Analysis of techniques used by threat actors can often be helpful in establishing the origin of the attack and the malware it uses. In this case... allowing us to establish a medium confidence link between them and a malware cluster known as PicassoLoader, a downloader toolkit.
Analysis of Dwnldr.dll shows that it is a DLL file with a .NET assembly embedded inside. The file is protected with ConfuserEx... The DLL file hosts a payload that appears to be a simplified variant of PicassoDownloader, a malware family also linked to Ghostwriter activity... Analysis of techniques used by threat actors can often be helpful in establishing the origin of the attack and the malware it uses. In this case... allowing us to establish a medium confidence link between them and a malware cluster known as PicassoLoader, a downloader toolkit.
Analysis of Dwnldr.dll shows that it is a DLL file with a .NET assembly embedded inside. The file is protected with ConfuserEx... The DLL file hosts a payload that appears to be a simplified variant of PicassoDownloader, a malware family also linked to Ghostwriter activity... Analysis of techniques used by threat actors can often be helpful in establishing the origin of the attack and the malware it uses. In this case... allowing us to establish a medium confidence link between them and a malware cluster known as PicassoLoader, a downloader toolkit.
For Ukrainian IP addresses, it delivers a RAR archive containing a JavaScript file. This file executes a JavaScript version of PicassoLoader, the group's payload downloader, which collects system information and sends it to attacker-controlled servers.
Key developments include the deployment of multiple variants of the group’s main payload downloader, named PicassoLoader by CERT-UA. Variants of this downloader are written in .NET, PowerShell, JavaScript, and C++.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
These tactics range from using phishing emails containing malicious ZIP files to deploying different families of malware.
CERT-UA ... зафіксовано сплеск активності угрупування UAC-0057, що полягала в розповсюдженні документів з макросами ... Вміст виявлених файлів ... стосувався реформи органів місцевого самоврядування ... оподаткування, а також тематики фінансово-економічних показників.
As a result the program bypasses the harmless file and instead locates and executes a batch or CMD script.
Upon running the cmd file, multiple VBS and Bat. files are created and launched to deploy the next-stage of malware named PicassoLoader.
та виконання JavaScript-коду, призначеного для завантаження зображення "113-1131910-clipart.svg", отримання за зміщенням та дешифрування за допомогою алгоритму Rabbit .NET-файлу
The file is protected with ConfuserEx... For this script, the attackers used a popular obfuscator tool called Macropack.
Once the file is downloaded, it is renamed and then saved to %APPDATA%\Roaming\Microsoft\SystemCertificates\CertificateCenter.dll ... This suggests that the CertificateCenter.dll file is not a binary as the file extension would suggest but rather contains program source code.
T1036.005 Masquerading: Match Legitimate Resource Name or Location
It does so by decrypting additional code of the assembly.
It launches an LNK file by using Mshta.exe utility that leads to the execution of the HTA file.
The DLL file is loaded with the following command line invocation: C:\Windows\System32\regsvr32.exe /u /s "C:\Temp\Realtek(r)Audio.dll"
the .NET ConfuserEx-obfuscated Downloader DLL ... is loaded with rundll32.exe and respective commandline arguments to run an exported function.
As a part of application protection provided by the obfuscator, the Downloader creates a copy of itself in memory, and then modifies it... It also uses a clever evasion technique, altering its own PE header in memory and breaking internal links to the .NET assembly.
Мережеві: backstagemerch[.]shop, empoweringparents[.]shop, lauramcinerney[.]shop ... https://backstagemerch.shop/the-simpsons/mens-freeze.html ...
Command and Control T1071.001 Application Layer Protocol: Web Protocols
136 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader malware used in a separate Ghostwriter campaign targeting Belarusian opposition activists and Ukrainian military and government entities via weaponized Excel documents.
Loader used by UAC-0057 (Ghostwriter).
A payload downloader used by FrostyNeighbor/Ghostwriter that collects system information and sends it to attacker-controlled servers, after which operators may choose to deliver a third-stage payload.
A long-standing payload downloader used by Ghostwriter/FrostyNeighbor. In this campaign, a JavaScript variant profiles the compromised host, collects system information such as username, machine name, OS version, boot time, and running processes, then reports to attacker-controlled servers every ten minutes. Based on operator review, it may receive and launch a further payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.