Home/Threat Actor/Ghostwriter / UNC1151
Threat Actor

Ghostwriter / UNC1151

ghostwriter · belarus · active since 2017

Ghostwriter / UNC1151 (Mandiant canonical naming UNC1151 for the cyber-espionage cluster + Ghostwriter for the broader influence-operations campaign) is a Belarus-aligned cyber-espionage and influence-operations hybrid cluster operationally attributed to the Belarusian government with HIGH confidence per Mandiant's November 16, 2021 canonical attribution publication, UNC1151 component active since at least 2017, Ghostwriter campaign tracking since 2020; operationally distinct from MoustachedBouncer (curated separately) through influence-operations primary mission vs embassy surveillance mission, regional-neighbor targeting (Ukraine / Lithuania / Latvia / Poland / Germany) vs foreign-embassies-within-Belarus targeting, credential- theft-via-spoofed-websites tradecraft vs AitM-at-ISP-level tradecraft, direct links to Belarusian military per Mandiant.

signature tradecraft includes credential theft via 200+ spoofed legitimate websites (Facebook, Google, Twitter, regional email providers, local/national government agencies), compromised-account-leveraging for disinformation dissemination, anti-NATO + anti-Lithuania-Poland narrative promotion, Belarusian state TV narrative amplification; canonical operations include June 2019 multi-country phishing (Poland, Lithuania, Latvia, Ukraine + Colombian / Irish / Swiss governments), post-August-2020 Belarusian elections operational pivot to anti-Lithuania + anti-Poland narratives, April 2021 Mandiant Ghostwriter-UNC1151 attribution + German Bundestag MP phishing targeting, Polish Email Scandal era 2021 (4,000+ target database), Mandiant November 16, 2021 high-confidence Belarus attribution revising prior September 2021 German government + EU Council Russia attribution.

September 2021 German government + EU Council formally identified Russia as sponsor following German parliamentary elections cyberattacks before Mandiant November 2021 revised assessment moved primary attribution to Belarus while acknowledging Russian contributions cannot be ruled out.

2nd Belarus-attributed cluster in the curated corpus complementing moustachedbouncer.

belarus confidence: high 8 aliases

Profile

Ghostwriter / UNC1151 (Mandiant canonical naming: UNC1151 for the cyber-espionage cluster providing operational support to the broader Ghostwriter information operations campaign) is a Belarus-aligned cyber-espionage and influence- operations hybrid cluster. The cluster is operationally attributed to the Belarusian government with HIGH confidence per Mandiant's November 16, 2021 canonical attribution publication, with MODERATE confidence Ghostwriter operations conducted with Belarusian sponsorship. UNC1151 has been active publicly since at least 2017.

Ghostwriter influence- operations campaign tracking began in 2020. The cluster is operationally distinguished within this curated corpus through its hybrid operational mission combining (a) traditional cyber-espionage and credential- theft activities (UNC1151 component) targeting government and private-sector entities across Ukraine, Lithuania, Latvia, Poland, and Germany.

and (b) information-operations / disinformation-campaign activities (Ghostwriter component) promoting Belarus-aligned narratives via fake news articles, compromised government official social media accounts, and Belarusian state television amplification. Operational phases: (1) UNC1151 cyber-espionage operational emergence (2017+). Earliest tracked cyber-espionage activity. Target set established: Ukraine, Lithuania, Latvia, Poland, Germany. Credential theft via spoofed Facebook, Google, Twitter, regional email providers, and local/national government agency websites. (2) Anti-NATO narrative promotion era (Pre-August 2020). 22 of 24 disinformation campaigns focused on anti- NATO narratives, false allegations of nuclear weapon deployment, NATO troops spreading COVID-19, crimes committed by NATO troops. (3) Post-August 2020 Belarusian elections operational pivot. Operations became "more distinctly aligned with Minsk's interests." Pivot to anti-Lithuania + anti-Poland narrative promotion. Belarusian opposition discrediting. September 2020 fake articles claimed Poland and Lithuania wanted NATO troops sent to Belarus. (4) Mandiant April 2021 initial Ghostwriter-UNC1151 attribution + German Bundestag MP targeting (April 2021). April 2021 Mandiant report linked UNC1151 to Ghostwriter operational support. German Bundestag MP phishing targeting operationally preceding September 2021 German federal elections. (5) Polish Email Scandal era (2021). UNC1151 created database of 4,000+ non-random targets.

obtained private email addresses + family member information. Compromised social media accounts of Polish officials used for Ghostwriter fake news dissemination. (6) Mandiant November 16, 2021 high-confidence Belarus attribution. Canonical revised attribution moving primary attribution from Russia (prior September 2021 German government + EU Council attribution) to Belarus with direct operational links to Belarusian military per Mandiant. (7) Russia-Ukraine war era continued operations (2022-2026). Sustained operational tempo with continued regional-neighbor focus. Continued integration of Ghostwriter narratives into Belarusian state television apparatus.

Signature operational tradecraft
  • Credential-theft-via-spoofed-legitimate-websites: signature cyber-espionage component tradecraft. Spoofs Facebook, Google, Twitter, regional email providers, and local/national government agency websites. 200+ identified credential theft domains.
  • Compromised-account-leveraging for disinformation dissemination: signature hybrid tradecraft connecting cyber-espionage component (UNC1151) with influence- operations component (Ghostwriter). Compromised Polish officials' social media accounts used to disseminate Ghostwriter fake news.
  • Anti-NATO + anti-Lithuania-Poland narrative promotion: signature influence-operations narrative themes operationally aligned with Belarus state-aligned geopolitical priorities.
  • Belarusian state TV narrative amplification: Ghostwriter narratives have been featured on Belarusian state television as fact, operationally integrating the cluster's influence operations into the Belarus state media apparatus.
  • Regional-neighbor geographic targeting: signature target set of Ukraine + Lithuania + Latvia + Poland + Germany, countries with strained bilateral relationships with Belarus.
  • Targets ministries of defense across regional-neighbor countries: signature government-targeting pattern with strong military intelligence-gathering focus.
  • Direct links to Belarusian military per Mandiant sensitively-sourced technical evidence, operationally placing the cluster within the broader Belarus military intelligence ecosystem. The cluster fills the Belarus-aligned influence-operations + cyber-espionage hybrid analytical cell in this curated corpus, complementing the broader Belarus-aligned coverage (moustachedbouncer for embassy surveillance). Ghostwriter / UNC1151 is operationally distinct from MoustachedBouncer (curated separately as moustachedbouncer.yaml) through: (a) signature influence-operations primary mission vs MoustachedBouncer's diplomatic-intelligence-collection mission; (b) signature regional-neighbor targeting (Ukraine / Lithuania / Latvia / Poland / Germany) vs MoustachedBouncer's foreign-embassies-within-Belarus targeting; (c) credential- theft-via-spoofed-websites tradecraft vs MoustachedBouncer's AitM-at-ISP-level tradecraft; (d) direct links to Belarusian military per Mandiant vs MoustachedBouncer's broader Belarus-state-aligned attribution. The 2nd Belarus-attributed cluster in the curated corpus.

Aliases

8
ghostwriterghostwriter influence operationghostwriter campaignunc1151unc-1151ghostwriter_unc1151ghostwriter belarusghostwriter_belarus

Notable Campaigns

10
2025-2026Continued Operations Through 2025-2026
2022-2024Russia-Ukraine War Era Continued Operations (2022-2024)
2021Mandiant April 2021 Initial Attribution, Ghostwriter Linked to UNC1151
2021German Bundestag MP Phishing Targeting (April 2021)
2021Polish Email Scandal, UNC1151 Targeting Polish Officials' Email Accounts (2021)
2021Mandiant November 16, 2021 High-Confidence Belarus Attribution
2020Anti-NATO Narrative Promotion Era (Pre-August 2020)
2020Post-August 2020 Belarusian Elections Operational Pivot
2019June 2019 Multi-Country Phishing Campaign
2017UNC1151 Operational Emergence (Since 2017)

Attribution & Reporting

Attributed by
Mandiant (Google Cloud Threat Intelligence)Microsoft Threat Intelligence CenterUkrainian CERT-UAGerman Federal GovernmentCouncil of the European UnionPolish CERTLithuanian National Cyber Security CentreSentinelLabsCrowdStrikeRecorded Future Insikt GroupTrend MicroSOPHOS X-OpsVSquare investigative consortiumDark ReadingSC Media
Key reporting
reportMandiant Threat Intelligence (Google Cloud): UNC1151 Assessed with High Confidence to have Links to Belarus, Ghostwriter Campaign Aligned with Belarusian Government Interests (November 16, 2021), canonical Belarus high-confidence attribution publication
reportMandiant: Ghostwriter + UNC1151 Initial Attribution Disclosure (April 2021), initial Ghostwriter-UNC1151 linkage report
reportVSquare Investigative Reporting: The Ghostwriter Scenario, Polish Email Scandal Documentation (Polish investigative journalism consortium)
reportGerman Federal Government + Council of the European Union: Russia Sponsor Identification of Ghostwriter Campaign (September 2021), superseded by Mandiant November 2021 Belarus attribution
reportMicrosoft Threat Intelligence: Belarus-Aligned + Russia-Aligned Cluster Tracking
reportUkrainian CERT-UA: UNC1151 Operational Tracking
reportPolish CERT: UNC1151 + Ghostwriter Operations Tracking
reportLithuanian National Cyber Security Centre: UNC1151 Tracking
reportSentinelLabs: Ghostwriter + UNC1151 Belarus Influence Operations Analysis
reportCrowdStrike: Belarus-Aligned Cluster Tracking
reportRecorded Future Insikt Group: Belarus State-Aligned Cyber Operations Tracking
reportTrend Micro: Belarus-Aligned + Russia-Aligned APT Tracking
reportSOPHOS X-Ops: Belarus-Aligned Cluster Tracking
reportDark Reading: Belarus Linked to Big European Disinformation Campaign (November 2021)
reportCyberScoop: Mandiant Links Belarus to Ghostwriter Campaign (November 2021)
reportMITRE ATT&CK Group G1011, UNC1151
reportMalpedia Actor Profile: UNC1151

Operational

State sponsor

Republic of Belarus state-aligned cyber-espionage and influence-operations cluster. Mandiant Threat Intelligence (Google Cloud) assesses with HIGH confidence that UNC1151 (the cyber-espionage component of the broader Ghostwriter operational ecosystem) is linked to the Belarusian government, formal attribution published November 16, 2021. Mandiant assesses with MODERATE confidence that Ghostwriter information operations are conducted with Belarusian sponsorship. The Belarus attribution operationally revised earlier Mandiant assessments (April 2021 report) that had characterized Ghostwriter operations as "aligned with Russian security interests." Per Mandiant analysis: "sensitively sourced technical evidence indicates that the operators behind UNC1151 are likely located in Minsk, Belarus" with researchers "directly observing links to the Belarusian military." Separate Mandiant technical evidence "supports a link" between UNC1151 and the Belarusian military specifically. The operational targeting pattern operationally supports the Belarus attribution: UNC1151 targets a specific country set (Ukraine, Lithuania, Latvia, Poland, Germany) that operationally aligns with the Belarus state's geopolitical interests, these countries have strained bilateral relationships with Belarus and have been operational targets of Belarusian state surveillance, counter-intelligence, and influence operations especially since the disputed August 2020 Belarusian presidential election. Mandiant notes "We cannot rule out Russian contributions to either UNC1151 or Ghostwriter. However, at this time, we have not uncovered direct evidence of such contributions" , though Mandiant has seen "high level TTP overlaps with Russian operations and much of the targeting and information operations are consistent with Russian operations." Operationally, the Belarus + Russia joint-coordination hypothesis is plausible given the close Russia-Belarus state alignment, but Mandiant's formal attribution maintains the Belarus primary attribution while acknowledging potential Russian contributions. Initially (in September 2021), the German government and Council of the European Union formally identified Russia as the sponsor of the Ghostwriter campaign following a series of cyberattacks determined to influence the outcome of parliamentary elections in Germany. Mandiant's subsequent November 2021 revised assessment moved the primary attribution from Russia to Belarus while acknowledging that Russian contributions cannot be ruled out. The cluster has been conducting cyber-espionage activities since at least 2017 (per Mandiant analysis), operationally predating the canonical Ghostwriter influence-operations campaign-tracking that began in 2020. The cluster operationally became "more distinctly aligned with Minsk's interests" especially following the disputed August 2020 Belarusian elections, operationally consistent with broader Belarus state-aligned operational priorities during the post-2020 elections crisis era and the subsequent Belarus-Lithuania-Poland border crisis, Belarus-EU sanctions crisis, and Russia-Ukraine war era. The cluster is operationally distinct from MoustachedBouncer (curated separately as moustachedbouncer.yaml, Belarus- aligned embassy surveillance cluster) through (a) signature influence-operations primary mission vs MoustachedBouncer's diplomatic-intelligence-collection mission.

(b) signature regional-neighbor targeting (Ukraine, Lithuania, Latvia, Poland, Germany) vs MoustachedBouncer's foreign-embassies- within-Belarus targeting.

(c) credential-theft-via-spoofed- websites + email-account-compromise tradecraft vs MoustachedBouncer's AitM-at-ISP-level tradecraft.

(d) direct links to Belarusian military per Mandiant vs MoustachedBouncer's broader Belarus-state-aligned attribution.

Motivations
influence_operations_disinformation, information_warfare, cyber_espionage_intelligence_collection, credential_theft_for_account_takeover, government_official_targeting, belarus_state_aligned_geopolitical_pressure, anti_nato_narrative_promotion_historical, anti_lithuania_anti_poland_narrative_promotion_post_2020, belarus_opposition_discrediting, polish_lithuanian_relations_destabilization, destabilization_of_internal_politics_in_nato_countries
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)32/60 · 53%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
METERPRETERMICROPSIA ADJACENT OVERLAPSPOOFED FACEBOOK CREDENTIAL THEFT PAGESSPOOFED GOOGLE CREDENTIAL THEFT PAGESSPOOFED LOCAL NATIONAL GOVERNMENT PAGESSPOOFED REGIONAL EMAIL PROVIDER PAGESSPOOFED TWITTER CREDENTIAL THEFT PAGES

CVEs Exploited

2
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin