> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
UNC1151 (GHOSTWRITER)
/actor/unc1151-ghostwriter/ · 0 intel reports
UNC1151, associated with the Ghostwriter influence operations campaign, is a threat actor with high-confidence attribution to the Belarusian government, with several cybersecurity firms and Western governments assessing significant coordination with Russian GRU intelligence services. The group conducts a distinctive blend of cyber intrusions and coordinated information operations , hacking government and media accounts to publish fabricated or manipulated content, then amplifying it through inauthentic social media networks to generate disinformation at scale.
Ghostwriter's influence operations have primarily targeted audiences in Lithuania, Latvia, Estonia, Poland, and Germany , NATO member states with historically complex relationships with both Russia and Belarus. Operations include publishing fabricated statements attributed to real military commanders claiming NATO forces had committed crimes against local populations, distributing forged government documents claiming NATO was planning to withdraw from the Baltic states, and creating false narratives about NATO military exercises designed to stoke anti-NATO sentiment.
The Ghostwriter methodology represents a sophisticated integration of technical intrusion capability with strategic communications: real government or media websites are compromised to lend credibility to fabricated content, which is then amplified through sockpuppet networks before the original compromise is discovered and removed. This "hack then amplify" approach creates a credibility halo that pure disinformation operations lack.
Following the Russian invasion of Ukraine in 2022, Ghostwriter dramatically expanded operations targeting Ukrainian audiences, military morale, and Western European public opinion about continued support for Ukraine , demonstrating the group's role as a persistent instrument of Belarusian and Russian hybrid warfare designed to fracture NATO cohesion and undermine Ukrainian resistance.
Cyber Espionage Tactics and Persistence Mechanisms: Operational tracking indicates that UNC1151 (Ghostwriter) executes long-term cyber espionage campaigns aligned with strategic intelligence requirements. The threat group weaponizes spear-phishing lures with malicious Office attachments, exploits unpatched edge appliances and VPN gateways, and establishes covert command-and-control (C2) channels using custom backdoors and legitimate administrative binaries. Defending against these advanced persistent threats requires comprehensive endpoint detection and response (EDR) visibility, continuous credential auditing, and proactive threat hunting across sensitive network enclaves.
> LINKED_INTEL_REPORTS (0)
[NULL] No intel reports found for this actor.