Skip to content
BelarusState-SponsoredActiveMITRE G1049

Ghostwriter

Belarusian military intelligence running information operations — compromises real journalists' accounts to publish fabricated stories under their bylines.

Open MITRE Navigator layer ↗Download profile JSON
Active
2016–present
Motivation
Information Operations, Espionage
Aliases
8
Exploited CVEs
2
ATT&CK techniques
8
Cited sources
6

Overview

Ghostwriter is the clearest documented fusion of network intrusion and information operations run by a single actor.

The pattern that named it: compromise the content management system of a legitimate regional news outlet, publish a fabricated article under the outlet's genuine branding, then amplify it through compromised or fake social media accounts before the publisher notices and removes it. The story circulates as authentic reporting from a real, trusted source. In several documented cases the group also compromised the email and social media accounts of real journalists and defence officials to publish forged statements under their names.

The content is consistently designed to undermine NATO's standing in Poland, Lithuania, and Latvia — fabricated stories of NATO soldiers committing crimes, forged letters announcing troop withdrawals, and false claims of contaminated equipment or planned aggression.

Mandiant assessed with high confidence in 2021 that UNC1151 — the intrusion cluster supporting the operation — is linked to the Belarusian government, and the EU sanctioned Belarusian individuals in connection with the activity. The German government has separately attributed Ghostwriter activity targeting parliamentarians to the operation, and Poland has publicly attributed a series of incidents to Belarusian and Russian services.

The group's technical capability is modest — credential phishing and webmail compromise — but its effect is disproportionate, because the payload is a story rather than a payload.

Attribution

Down to the named unit where public evidence supports it.

BelarusBelarusian military intelligence, with assessed Russian coordinationHigh confidence

Mandiant assessed with high confidence in November 2021 that UNC1151 is linked to the Belarusian government, and with moderate confidence that the Belarusian military is involved in the Ghostwriter information operation. The EU imposed sanctions in connection with the campaign, and Germany formally attributed Ghostwriter activity against parliamentarians and political parties. Poland has publicly attributed related incidents to Belarusian and Russian services acting in coordination.

Attributing sources

Cross-vendor naming crosswalk

8 designators across 7 organisations.

1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • UNC1151

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Storm-0257

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Ghostwriter

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • UNC1151
  • GhostwriterpartialGhostwriter names the information operation; UNC1151 names the intrusion cluster supporting it. Frequently conflated.

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Recorded Future Insikt Group

index ↗
  • TA445Proofpoint designator, widely cross-referenced

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

Proofpoint

index ↗
  • TA445

TA### ('Threat Actor'), numbered sequentially in order of first tracking.

CISA / NSA / FBI

index ↗
  • Ghostwriter

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

PolandLithuaniaLatviaUkraineGermanyEstoniaBelarus

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

PicassoLoaderloader

Loader using steganographic payload delivery, observed in campaigns against Ukrainian and Polish targets.

Shared, commodity & living-off-the-land

Credential phishing kitsutility

Cloned webmail and government SSO portals harvesting credentials from journalists and officials.

AgentTesla / njRATbackdoor

Commodity RATs deployed after initial credential compromise.

CMS compromiselotl

Direct access to news outlet content management systems to publish fabricated articles under genuine branding.

MicroBackdoorbackdoor

Open-source backdoor adopted for operations against Ukrainian government targets.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by Ghostwriter
CVE-2022-30190KEVransomware7.81 Jun 2022Follina MSDT exploit used against Ukrainian and Polish government targets in phishing campaigns.SRCCERT-UA
CVE-2017-0199KEVransomware7.81 Jan 2020OLE2link RTF exploit delivering commodity RATs to regional government targets.SRCMandiant

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

6 stages · 8 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
8 techniques across 6 tactics · 5 with actor-specific notes

Resource Development

1

Initial Access

3

Defense Evasion

1

Impact

1

Campaign timeline

  1. NATO-Focused Information Operations

    Compromise of regional news outlet content management systems to publish fabricated articles under genuine branding, alongside forged statements posted from compromised accounts of real journalists and officials — all designed to undermine NATO's standing in Poland and the Baltics.

    Media & JournalismGovernmentDefensePolitical Organizations

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.