Ghostwriter
Also reported as UNC1151, TA445, UAC-0057, PUSHCHA, DEV-0257 and 4 other names. Linked to Belarus by three sources.
Reports per quarter
Techniques seen in the last two years
- T1027 2 reports
- T1057 2 reports
- T1059 2 reports
- T1027.009 1 report
- T1036.005 1 report
- T1041 1 report
- T1053.005 1 report
- T1071 1 report
- T1071.001 1 report
- T1082 1 report
Show all 21 techniques Show fewer
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2017-0199 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-14882 KEV
- CVE-2021-1636
- CVE-2021-1879 KEV
- CVE-2021-21166 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26868
- CVE-2021-30551 KEV
- CVE-2021-32648 KEV
- CVE-2021-33742 KEV
- CVE-2021-34527 KEV ransomware
Show all 27 CVEs Show fewer
- CVE-2021-40444 KEV ransomware
- CVE-2022-26134 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2023-3519 KEV ransomware
- CVE-2023-36025 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2024-21412 KEV ransomware
- CVE-2024-27564
- CVE-2024-30051 KEV ransomware
- CVE-2024-42009 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2025-24813 KEV
- CVE-2025-49704 KEV ransomware
- CVE-2025-66376 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor RiskIQ Threat Intelligence Roundup: Campaigns Targeting Ukraine and Global Malware Infrastructure | RiskIQ
Show all 97 reports Show fewer
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
-
StrikeReady — AI-Powered Security Command Center
The original link failed its last check. Original publisher Detailsfor StrikeReady — AI-Powered Security Command Center
-
CVE-2024-21412_ Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CVE-2024-21412_ Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
-
Ukraine remains Russia’s biggest cyber focus in 2023
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ukraine remains Russia’s biggest cyber focus in 2023
-
UNC1151 Group Indicators of Compromise (IOC)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UNC1151 Group Indicators of Compromise (IOC)
-
Evacuation and Humanitarian Documents used to Spear Phish Ukrainian Entities
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evacuation and Humanitarian Documents used to Spear Phish Ukrainian Entities
-
Development of UNC1151-Ghostwriter attack techniques
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Development of UNC1151-Ghostwriter attack techniques
-
Continued cyber activity in Eastern Europe observed by TAG
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Continued cyber activity in Eastern Europe observed by TAG
-
The IO Offensive Information Operations Surrounding the Russian Invasion of Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The IO Offensive Information Operations Surrounding the Russian Invasion of Ukraine
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor UNC1151 Assessed with High Confidence to have Links to Belarus, Ghostwriter Campaign Aligned with Belarusian Government Interests _ Mandiant
-
Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian Cyber Attack campaigns and actors - NOBELIUM has struck again.pdf
-
Russian cyber attack campaigns and actors.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors.pdf
-
Update on cyber activity in Eastern Europe
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Update on cyber activity in Eastern Europe
-
Attack Graph Response to UNC1151 Continued Targeting of Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attack Graph Response to UNC1151 Continued Targeting of Ukraine
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Asylum Ambuscade_ State Actor Uses Compromised Private Ukrainian Military Emails to Target European Governments and Refugee Movement _ Proofpoint US
-
Microsoft Obtains Court Order to Take Down Domains Used to Target Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Obtains Court Order to Take Down Domains Used to Target Ukraine
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ukraine CyberWar Overview
-
New spear phishing campaign targets Russian dissidents
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor New spear phishing campaign targets Russian dissidents
-
Tracking cyber activity in Eastern Europe
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking cyber activity in Eastern Europe
-
New spear phishing campaign targets Russian dissidents
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New spear phishing campaign targets Russian dissidents
-
Threat Thursday- SunSeed Malware Targets Ukraine Refugee Aid Efforts
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Thursday- SunSeed Malware Targets Ukraine Refugee Aid Efforts
-
Behind the hack-and-leak scandal in Poland (UNC1151)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Behind the hack-and-leak scandal in Poland (UNC1151)
-
GhostWriter - UNC1151 adopts MicroBackdoor Variants in Cyber Operations against Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GhostWriter - UNC1151 adopts MicroBackdoor Variants in Cyber Operations against Ukraine
-
An update on the threat landscape (APT28, UNC1151, MUSTANG PANDA)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor An update on the threat landscape (APT28, UNC1151, MUSTANG PANDA)
-
Domains Linked to Phishing Attacks Targeting Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Domains Linked to Phishing Attacks Targeting Ukraine
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What is HermeticWiper – An Analysis of the Malware and Larger Threat Landscape in the Russian Ukrainian War
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Asylum Ambuscade: State Actor Uses Compromised Private Ukrainian Military Emails to Target European Governments and Refugee Movement
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Asylum Ambuscade_State Actor Uses Compromised Private Ukrainian Military Emails to Target European Governments and Refugee Movement
-
Meta- Ukrainian officials, military targeted by Ghostwriter hackers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Meta- Ukrainian officials, military targeted by Ghostwriter hackers
-
Cyber threat activity in Ukraine- analysis and resources
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber threat activity in Ukraine- analysis and resources
-
Meta’s Ongoing Efforts Regarding Russia’s Invasion of Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Meta’s Ongoing Efforts Regarding Russia’s Invasion of Ukraine
-
Russia or Ukraine- Hacking groups take sides
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russia or Ukraine- Hacking groups take sides
-
Anticipating Cyber Threats as the Ukraine Crisis Escalates
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Anticipating Cyber Threats as the Ukraine Crisis Escalates
-
‘Ghostwriter’ Looks Like a Purely Russian Op - Except It's Not
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ‘Ghostwriter’ Looks Like a Purely Russian Op - Except It's Not
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UNC1151 Assessed with High Confidence to have Links to Belarus, Ghostwriter Campaign Aligned with Belarusian Government Interests
-
UNC1151_Assessed-with-High-Confidence-to-have-Links-to-Belarus_Mandiant
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor UNC1151_Assessed-with-High-Confidence-to-have-Links-to-Belarus_Mandiant
-
Diving Deep into UNC1151’s Infrastructure- Ghostwriter and beyond
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Diving Deep into UNC1151’s Infrastructure- Ghostwriter and beyond
-
The Ghostwriter Scenario (UNC1151)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Ghostwriter Scenario (UNC1151)
-
Polish intelligence agencies link cyberattack to Russia (UNC1151)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Polish intelligence agencies link cyberattack to Russia (UNC1151)
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Statement by the Vice-President of the Council of Ministers, Chairman of the Committee for National Security and Defense Affairs, Jarosław Kaczyński (about UNC1151)
-
Indicators Over Cocktails- Exporting Indicators from Iris (UNC1151)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Indicators Over Cocktails- Exporting Indicators from Iris (UNC1151)
-
unc1151-ghostwriter-update-report.pdf
The original link failed its last check. Original publisher Detailsfor unc1151-ghostwriter-update-report.pdf
-
unc1151-ghostwriter-update-report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor unc1151-ghostwriter-update-report
-
Attack of the -chaos troops- (Ghostwriter)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attack of the -chaos troops- (Ghostwriter)
-
Russian group -Ghostwriters- apparently attacked parliamentarians
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian group -Ghostwriters- apparently attacked parliamentarians
-
Russian cyber attack campaigns and actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian cyber attack campaigns and actors
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 'Ghostwriter' Influence Campaign- Unknown Actors Leverage Website Compromises and Fabricated Content to Push Narratives Aligned With Russian Security Interests
-
Ghostwriter-Influence-Campaign.pdf
The original link failed its last check. Original publisher Detailsfor Ghostwriter-Influence-Campaign.pdf
Newest first. Details opens the report in Explore.