German authorities said the Ghostwriter group targeted members of the Bundestag and state parliaments in a phishing campaign designed to seize private email accounts. At least seven federal lawmakers and 31 state parliament members were reportedly affected, along with political activists in Hamburg and Bremen. The attackers allegedly posed as legitimate security notifications from email providers, with addresses hosted by GMX and T-Online singled out in the operation.
The activity fits Ghostwriter’s broader pattern of combining credential theft, social media and account takeovers, website compromises, fabricated content, and hack-and-leak tactics to push narratives aligned with anti-NATO and regional political objectives. Earlier reporting tied the campaign to Russian security interests and suspected GRU involvement, while later threat intelligence assessments attributed the operation to Belarus-linked actors, possibly connected to the Belarusian military and operating from Minsk, after the group’s focus expanded to dissidents, media figures, and neighboring governments including Poland and Lithuania.

See the actors and campaigns active against you right now.
13 events from the most recent confirmed update back to the earliest known activity.
By April 2021, Mandiant attributed broader activity to Ghostwriter beyond fake articles, including compromising social media accounts of government officials to spread misinformation and targeting politicians in hacking and leaking operations.
After Belarus' disputed August 2020 election, Mandiant observed Ghostwriter shift toward Belarus-specific issues, including targeting dissidents, media figures, and neighboring governments such as Poland and Lithuania.
FireEye published research in July 2020 examining Ghostwriter as an influence campaign that used website compromises and fabricated content aligned with Russian security interests.
In the previous year, Germany's Federal Prosecutor obtained an arrest warrant for Russian hacker Dmitri Badin, alleging he played a key role in the 2015 Bundestag cyberattack and worked for the GRU.
On 25 September 2019, a false story published on a Baltic website claimed German NATO soldiers had desecrated a Jewish cemetery in Lithuania and used a manipulated photo.
A fabricated report dated 7 June 2018 claimed that a Lithuanian child had been run over by a NATO tank as part of Ghostwriter's anti-NATO disinformation efforts.
A false report dated 28 March 2017 alleged that a German Bundeswehr officer stationed with NATO in Lithuania was a Russian spy, illustrating Ghostwriter's early disinformation activity.
FireEye said the Ghostwriter influence campaign had been running since 2017, initially focusing on Lithuania, Latvia, and Poland with narratives intended to stir sentiment against NATO.
Mandiant concluded that the long-running Ghostwriter hacking and disinformation campaign was tied to Belarus rather than Russia, citing technical details suggesting operators were in Minsk and possible links to the Belarusian military.
In August, a Ghostwriter operation promoted a false narrative accusing migrants of committing crimes in Poland and Lithuania.
At the end of September, the European Union said some member states had associated Ghostwriter with the Russian state.
At least seven Bundestag members and 31 state parliament members were targeted in a phishing campaign aimed at taking over private email accounts; activists in Hamburg and Bremen were also reportedly attacked.
Germany's BSI and BfV sent warning letters to potential victims about a new phishing wave impersonating provider security messages and targeting GMX and T-Online addresses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
wired.com
Open sourcespiegel.de
Open sourcefireeye.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.