Mandiant said the long-running Ghostwriter operation has continued to target audiences in Lithuania, Latvia, and Poland with cyber-enabled influence activity promoting narratives critical of NATO’s presence in Eastern Europe. The company reported that the campaign broadened beyond its earlier methods, expanding its narratives, targeting, and tactics while increasingly focusing on domestic political disruption in Poland through the use of compromised social media accounts belonging to Polish right-leaning officials.
According to Mandiant, the newer operations were conducted in Polish and English and relied less on website compromises, spoofed emails, and inauthentic personas than earlier Ghostwriter activity. Investigators found no evidence that social media platforms themselves were breached, assessing instead that attackers likely gained access through compromised email accounts and stolen credentials. Mandiant said newly obtained technical evidence supports a high-confidence assessment that espionage group UNC1151 conducts at least some components of Ghostwriter, and added that the group expanded credential-theft operations to target German politicians starting in 2021.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Mandiant said with high confidence that UNC1151 has links to the Belarusian government and that Ghostwriter activity is aligned with Belarusian government interests. The report said the campaign's messaging shifted after Belarus's disputed August 2020 election to defend Minsk, discredit the Belarusian opposition, and target Lithuania and Poland.
Based on newly obtained technical evidence, Mandiant assessed with high confidence that UNC1151 conducts at least some components of Ghostwriter influence activity, while noting it could not conclusively attribute all aspects of the campaign to the group.
Mandiant observed newer Ghostwriter operations using compromised social media accounts of Polish right-leaning officials to drive domestic political disruption in Poland. These operations were conducted in Polish and English and relied less on website compromises, spoofed emails, or inauthentic personas.
Since the start of 2021, Mandiant observed UNC1151 broaden its credential theft operations beyond earlier activity to include German politicians.
Mandiant's initial public report described Ghostwriter as an ongoing cyber-enabled influence operation targeting audiences in Lithuania, Latvia, and Poland with narratives critical of NATO's presence in Eastern Europe.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
mandiant.com
Open sourcemandiant.com
Open sourcemandiant.com
Open sourcefireeye.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.