{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "unc1151",
    "slug": "ghostwriter",
    "name": "Ghostwriter",
    "shortName": "Ghostwriter",
    "country": "Belarus",
    "countryCode": "BY",
    "sponsorship": "state-sponsored",
    "status": "active",
    "activeSince": "2016",
    "prominence": 72,
    "mitreGroupId": "G1049",
    "tagline": "Belarusian military intelligence running information operations — compromises real journalists' accounts to publish fabricated stories under their bylines.",
    "bio": "Ghostwriter is the clearest documented fusion of network intrusion and information operations run by a single actor.\n\nThe pattern that named it: compromise the content management system of a legitimate regional news outlet, publish a fabricated article under the outlet's genuine branding, then amplify it through compromised or fake social media accounts before the publisher notices and removes it. The story circulates as authentic reporting from a real, trusted source. In several documented cases the group also compromised the email and social media accounts of real journalists and defence officials to publish forged statements under their names.\n\nThe content is consistently designed to undermine NATO's standing in Poland, Lithuania, and Latvia — fabricated stories of NATO soldiers committing crimes, forged letters announcing troop withdrawals, and false claims of contaminated equipment or planned aggression.\n\nMandiant assessed with high confidence in 2021 that UNC1151 — the intrusion cluster supporting the operation — is linked to the Belarusian government, and the EU sanctioned Belarusian individuals in connection with the activity. The German government has separately attributed Ghostwriter activity targeting parliamentarians to the operation, and Poland has publicly attributed a series of incidents to Belarusian and Russian services.\n\nThe group's technical capability is modest — credential phishing and webmail compromise — but its effect is disproportionate, because the payload is a story rather than a payload.",
    "attribution": {
      "sponsor": "Belarus",
      "service": "Belarusian military intelligence, with assessed Russian coordination",
      "confidence": "high",
      "summary": "Mandiant assessed with high confidence in November 2021 that UNC1151 is linked to the Belarusian government, and with moderate confidence that the Belarusian military is involved in the Ghostwriter information operation. The EU imposed sanctions in connection with the campaign, and Germany formally attributed Ghostwriter activity against parliamentarians and political parties. Poland has publicly attributed related incidents to Belarusian and Russian services acting in coordination.",
      "sources": [
        {
          "org": "Mandiant",
          "title": "UNC1151 Assessed with High Confidence to have Links to Belarus, Ghostwriter Campaign Aligned with Belarusian Government Interests",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/unc1151-linked-to-belarus-government",
          "date": "2021-11-16"
        },
        {
          "org": "Council of the European Union",
          "title": "EU sanctions in response to hybrid threats and information manipulation",
          "url": "https://www.consilium.europa.eu/en/press/press-releases/",
          "date": "2024-12-16"
        }
      ]
    },
    "motivations": [
      "information-operations",
      "espionage"
    ],
    "targetSectors": [
      "Government",
      "Media & Journalism",
      "Defense",
      "Political Organizations",
      "NGO & Civil Society",
      "Education"
    ],
    "targetCountries": [
      "Poland",
      "Lithuania",
      "Latvia",
      "Ukraine",
      "Germany",
      "Estonia",
      "Belarus"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "UNC1151",
        "url": "https://attack.mitre.org/groups/G1049/",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "UNC1151",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "Ghostwriter",
        "correlation": "partial",
        "note": "Ghostwriter names the information operation; UNC1151 names the intrusion cluster supporting it. Frequently conflated."
      },
      {
        "org": "microsoft",
        "name": "Storm-0257",
        "correlation": "exact"
      },
      {
        "org": "recordedfuture",
        "name": "TA445",
        "correlation": "exact",
        "note": "Proofpoint designator, widely cross-referenced"
      },
      {
        "org": "proofpoint",
        "name": "TA445",
        "correlation": "exact"
      },
      {
        "org": "cisa",
        "name": "Ghostwriter",
        "correlation": "exact"
      },
      {
        "org": "crowdstrike",
        "name": "Ghostwriter",
        "correlation": "exact"
      }
    ],
    "tools": [
      {
        "name": "Credential phishing kits",
        "type": "utility",
        "custom": false,
        "description": "Cloned webmail and government SSO portals harvesting credentials from journalists and officials."
      },
      {
        "name": "AgentTesla / njRAT",
        "type": "backdoor",
        "custom": false,
        "description": "Commodity RATs deployed after initial credential compromise."
      },
      {
        "name": "CMS compromise",
        "type": "lotl",
        "custom": false,
        "description": "Direct access to news outlet content management systems to publish fabricated articles under genuine branding."
      },
      {
        "name": "PicassoLoader",
        "type": "loader",
        "custom": true,
        "description": "Loader using steganographic payload delivery, observed in campaigns against Ukrainian and Polish targets."
      },
      {
        "name": "MicroBackdoor",
        "type": "backdoor",
        "custom": false,
        "description": "Open-source backdoor adopted for operations against Ukrainian government targets."
      }
    ],
    "techniques": [
      {
        "tCode": "T1566.002",
        "name": "Phishing: Spearphishing Link",
        "tactic": "Initial Access",
        "note": "Credential harvesting against journalists, officials, and parliamentarians"
      },
      {
        "tCode": "T1078",
        "name": "Valid Accounts",
        "tactic": "Initial Access",
        "note": "Compromised journalist and official accounts used to publish forged content"
      },
      {
        "tCode": "T1585.001",
        "name": "Establish Accounts: Social Media Accounts",
        "tactic": "Resource Development",
        "note": "Amplification network for fabricated stories"
      },
      {
        "tCode": "T1491.002",
        "name": "Defacement: External Defacement",
        "tactic": "Impact",
        "note": "Fabricated articles published on legitimate news sites"
      },
      {
        "tCode": "T1189",
        "name": "Drive-by Compromise",
        "tactic": "Initial Access"
      },
      {
        "tCode": "T1114.002",
        "name": "Email Collection: Remote Email Collection",
        "tactic": "Collection"
      },
      {
        "tCode": "T1204.002",
        "name": "User Execution: Malicious File",
        "tactic": "Execution"
      },
      {
        "tCode": "T1027.003",
        "name": "Obfuscated Files or Information: Steganography",
        "tactic": "Defense Evasion",
        "note": "PicassoLoader payload concealment"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2022-30190",
        "firstExploited": "2022-06-01",
        "usage": "Follina MSDT exploit used against Ukrainian and Polish government targets in phishing campaigns.",
        "source": {
          "org": "CERT-UA",
          "title": "UAC-0057 (GhostWriter) activity reporting",
          "url": "https://cert.gov.ua/",
          "date": "2022-06-20"
        }
      },
      {
        "cveId": "CVE-2017-0199",
        "firstExploited": "2020-01-01",
        "usage": "OLE2link RTF exploit delivering commodity RATs to regional government targets.",
        "source": {
          "org": "Mandiant",
          "title": "UNC1151 Assessed with High Confidence to have Links to Belarus",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/unc1151-linked-to-belarus-government",
          "date": "2021-11-16"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "apt28",
        "type": "operational-overlap",
        "confidence": "moderate",
        "note": "Aligned messaging objectives and overlapping targets in Poland and the Baltics; assessed Russian coordination with the Belarusian operation."
      },
      {
        "relatedActorId": "gamaredon",
        "type": "operational-overlap",
        "confidence": "moderate",
        "note": "Both target Ukrainian government entities with overlapping phishing infrastructure patterns."
      }
    ],
    "reports": [
      {
        "org": "Mandiant",
        "title": "UNC1151 Assessed with High Confidence to have Links to Belarus",
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/unc1151-linked-to-belarus-government",
        "date": "2021-11-16"
      },
      {
        "org": "Mandiant / FireEye",
        "title": "Ghostwriter Influence Campaign: Unknown Actors Leverage Website Compromises and Fabricated Content",
        "url": "https://www.mandiant.com/resources/reports/ghostwriter-influence-campaign",
        "date": "2020-07-28"
      }
    ],
    "campaigns": [
      {
        "id": "ghostwriter-nato",
        "actorId": "unc1151",
        "name": "NATO-Focused Information Operations",
        "date": "2017-01-01",
        "significance": "major",
        "targetSectors": [
          "Media & Journalism",
          "Government",
          "Defense",
          "Political Organizations"
        ],
        "targetCountries": [
          "Poland",
          "Lithuania",
          "Latvia",
          "Germany"
        ],
        "cveIds": [],
        "summary": "Compromise of regional news outlet content management systems to publish fabricated articles under genuine branding, alongside forged statements posted from compromised accounts of real journalists and officials — all designed to undermine NATO's standing in Poland and the Baltics.",
        "sources": [
          {
            "org": "Mandiant / FireEye",
            "title": "Ghostwriter Influence Campaign",
            "url": "https://www.mandiant.com/resources/reports/ghostwriter-influence-campaign",
            "date": "2020-07-28"
          }
        ]
      }
    ],
    "flag": "🇧🇾",
    "profile": "/apt/ghostwriter/"
  }
}