Resource Development
1 technique·derived
Amplification network for fabricated stories.
Belarusian military intelligence running information operations — compromises real journalists' accounts to publish fabricated stories under their bylines.
Ghostwriter is the clearest documented fusion of network intrusion and information operations run by a single actor.
The pattern that named it: compromise the content management system of a legitimate regional news outlet, publish a fabricated article under the outlet's genuine branding, then amplify it through compromised or fake social media accounts before the publisher notices and removes it. The story circulates as authentic reporting from a real, trusted source. In several documented cases the group also compromised the email and social media accounts of real journalists and defence officials to publish forged statements under their names.
The content is consistently designed to undermine NATO's standing in Poland, Lithuania, and Latvia — fabricated stories of NATO soldiers committing crimes, forged letters announcing troop withdrawals, and false claims of contaminated equipment or planned aggression.
Mandiant assessed with high confidence in 2021 that UNC1151 — the intrusion cluster supporting the operation — is linked to the Belarusian government, and the EU sanctioned Belarusian individuals in connection with the activity. The German government has separately attributed Ghostwriter activity targeting parliamentarians to the operation, and Poland has publicly attributed a series of incidents to Belarusian and Russian services.
The group's technical capability is modest — credential phishing and webmail compromise — but its effect is disproportionate, because the payload is a story rather than a payload.
Down to the named unit where public evidence supports it.
Mandiant assessed with high confidence in November 2021 that UNC1151 is linked to the Belarusian government, and with moderate confidence that the Belarusian military is involved in the Ghostwriter information operation. The EU imposed sanctions in connection with the campaign, and Germany formally attributed Ghostwriter activity against parliamentarians and political parties. Poland has publicly attributed related incidents to Belarusian and Russian services acting in coordination.
Attributing sources
8 designators across 7 organisations.
1 designator is marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Loader using steganographic payload delivery, observed in campaigns against Ukrainian and Polish targets.
Shared, commodity & living-off-the-land
Cloned webmail and government SSO portals harvesting credentials from journalists and officials.
Commodity RATs deployed after initial credential compromise.
Direct access to news outlet content management systems to publish fabricated articles under genuine branding.
Open-source backdoor adopted for operations against Ukrainian government targets.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by Ghostwriter | ||
|---|---|---|---|---|
| CVE-2022-30190KEVransomware | 7.8 | Microsoft Windows MSDTMicrosoft | 1 Jun 2022 | Follina MSDT exploit used against Ukrainian and Polish government targets in phishing campaigns.SRCCERT-UA ↗ |
| CVE-2017-0199KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 Jan 2020 | OLE2link RTF exploit delivering commodity RATs to regional government targets.SRCMandiant ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
1 technique·derived
Amplification network for fabricated stories.
3 techniques·derived
Credential harvesting against journalists, officials, and parliamentarians. Compromised journalist and official accounts used to publish forged content.
1 technique·derived
Malicious File.
1 technique·derived
PicassoLoader payload concealment.
1 technique·derived
Remote Email Collection.
1 technique·derived
Fabricated articles published on legitimate news sites.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Amplification network for fabricated stories
Credential harvesting against journalists, officials, and parliamentarians
Compromised journalist and official accounts used to publish forged content
PicassoLoader payload concealment
Fabricated articles published on legitimate news sites
Compromise of regional news outlet content management systems to publish fabricated articles under genuine branding, alongside forged statements posted from compromised accounts of real journalists and officials — all designed to undermine NATO's standing in Poland and the Baltics.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Aligned messaging objectives and overlapping targets in Poland and the Baltics; assessed Russian coordination with the Belarusian operation.
Both target Ukrainian government entities with overlapping phishing infrastructure patterns.
Curated links to the reports that established what is known about this group.