Threat intelligence
- Suspected origin
- Belarus
- First seen
- 2017-01-01 00:00:00
- Motivation
- Information theft and espionage, Sabotage and destruction
- Targeted sectors
- Defense, Education, Government, Media
- Targeted countries
- Belarus
- TLP
- WHITE
(FireEye) Mandiant Threat Intelligence has tied together several information operations that we assess with moderate confidence comprise part of a broader influence campaign—ongoing since at least March 2017—aligned with Russian security interests. The operations have primarily targeted audiences in Lithuania, Latvia, and Poland with narratives critical of the North Atlantic Treaty Organization’s (NATO) presence in Eastern Europe, occasionally leveraging other themes such as anti-U.S. and COVID-19-related narratives as part of this broader anti-NATO agenda. We have dubbed this campaign “Ghostwriter.”
Many, though not all of the incidents we suspect to be part of the Ghostwriter campaign, appear to have leveraged website compromises or spoofed email accounts to disseminate fabricated content, including falsified news articles, quotes, correspondence and other documents designed to appear as coming from military officials and political figures in the target countries.
Also known as
DEV-0257PUSHCHAStorm-0257TA445UAC-0051UAC-0057UNC1151White Lynx
Coverage 4
phishing
A Belarus-linked hacking group, GhostWriter (UNC1151/Storm-0257), has expanded its phishing operations to target the personal Gmail accounts of Polish public figures and their families. The group’s tactics involve creati…

phishing
The Ghostwriter threat actor, linked to Belarus, has been conducting a phishing campaign targeting Ukrainian government entities since the spring of 2026. This campaign utilizes lures related to the Prometheus online lea…

threat-intel
A Belarus-linked hacking group, GhostWriter (UNC1151/Storm-0257), is conducting a new espionage campaign targeting Ukrainian government officials. The operation utilizes sophisticated phishing emails disguised as trainin…

threat-intel
FrostyNeighbor, a long-running cyberespionage group allegedly linked to Belarus, is continuing its operations targeting governmental organizations in Ukraine and other Eastern European countries. The latest activity invo…