UNC1151, also known as Ghostwriter, UAC-0057, FrostyNeighbor, and Storm-0257, is a suspected state-sponsored, Belarus-aligned threat actor engaged in cyber espionage, credential harvesting, malware delivery, and support to information operations. Multiple sources in the content describe Ghostwriter as a long-running cyber-enabled influence campaign targeting Lithuania, Latvia, and Poland with anti-NATO narratives, and assess UNC1151 as conducting at least some components of that activity. The content also notes reporting that Ghostwriter/UNC1151 has been associated with the governments of Belarus and Russia, and that researchers have linked the group to Belarusian state intelligence or described its activity as aligned with Belarusian government interests. The actor has repeatedly targeted Poland, Ukraine, Belarusian opposition figures, and government organizations. Reported victims and target sets include Polish citizens, politicians, journalists, researchers, public administration and law enforcement personnel, family and social contacts of primary targets, Belarusian pro-democracy politician Yury Hubarevich, Belarusian opposition activists, Ukrainian military and government organizations, and government entities in Germany. The content also states that the group has targeted Gmail users since March 2026 after previously focusing on Polish providers such as Onet, Wirtualna Polska, and Interia. Observed tradecraft includes sustained credential-phishing and spear-phishing campaigns, often impersonating Google security alerts or Gmail administrator notifications, using fake login pages to steal usernames, passwords, and two-factor authentication codes in real time, including SMS and authenticator-app codes. Infrastructure described in the content includes throwaway domains under .icu, .digital, and .top, Netlify-hosted phishing pages, compromised Polish and Ukrainian websites, and WebSocket-based real-time credential relay. The actor has repeatedly retargeted the same victims and used BCC-based delivery and fluent Polish-language lures. UNC1151 has also been attributed with malware campaigns using weaponized Office documents, PDFs, HTAs, macros, and LNK-based execution chains. Reported malware and tooling associated with the actor in the content include OYSTERBLUES, PicassoLoader/PicassoDownloader, Cobalt Strike Beacon, and related downloader chains using regsvr32.exe, rundll32.exe, and MSBuild.exe. Recent reporting cited in the content links UNC1151 to 2024-2025 campaigns using malicious Excel documents and HTA payloads against Ukrainian and Polish targets, including decoy documents, obfuscated VBA, ConfuserEx-protected .NET downloaders, and staged payload retrieval from attacker-controlled domains. The content further describes UNC1151 as using intrusion capabilities in complex information operations and hack-and-leak style activity. Public reporting cited here states that Polish authorities attributed attacks on thousands of Polish email and social media accounts to UNC1151 and linked the activity to Russian special services, while EU reporting associated Ghostwriter activity with the Russian state. Mandiant states it has high-confidence technical evidence linking UNC1151 to at least some Ghostwriter components, but not all Ghostwriter activity conclusively.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 malware families attributed to this actor across reporting.
10 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
CERT Poland on Friday warned that threat actors are exploiting a Roundcube XSS flaw in a spear-phishing campaign aimed at credential theft. CERT Poland attributed the activity to the Belarusian hacking group UNC1151. Tracked as CVE-2024-42009, the flaw leads to JavaScript code execution when opening an email.
CVE-2025-27915 is a stored XSS flaw in Zimbra Collaboration Suite (versions 9.0–10.1) caused by improper HTML sanitization in ICS files. When victims open an email with a malicious ICS entry, JavaScript executes via an <ontoggle> event, allowing attackers to hijack sessions, set email redirects, and exfiltrate data.
CERT-UA reported a cyberattack by UAC-0057 involving the file "Збірник_тез_НУОУ_23.rar", which contains an exploit for CVE-2023-38831. Successful exploitation leads to execution of a BAT file, then an LNK file, then an HTA via mshta.exe, ultimately delivering Cobalt Strike Beacon. The notice also states there is active exploitation of CVE-2023-38831 in WinRAR and that a PoC for generating ZIP archives with the required structure is publicly available.
286 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting targeted spear-phishing and credential theft operations against politically sensitive targets in Belarus and Ukraine, including fake Google login pages and phishing pages impersonating Ukrainian portals.
Conducted a spear-phishing campaign against government organizations using compromised accounts to deliver the OYSTERBLUES information stealer.
Conducting broad credential phishing and spear-phishing campaigns, including Gmail account phishing and impersonation of Ukrainian portals, targeting individuals in Belarus, Poland, and Ukraine.
Conducting a high-intensity Gmail credential phishing campaign against high-profile Polish targets, including politicians, journalists, researchers, public officials, and their close contacts; also associated with influence and disinformation operations and likely serving espionage objectives.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.