Ghostwriter

THREAT ACTOR PROFILE

Ghostwriter

Ghostwriter

Ghostwriter

UNC1151

Ghostwriter is a Belarus-linked group that pairs credential phishing with influence operations against Poland, Ukraine, Belarus and the wider region. It impersonates Google and local email providers to steal passwords and two-factor codes, and it has supported disinformation campaigns, defacements and malware delivery aligned with Belarusian and Russian interests.

Belarus

Government / Media / Civil society

First seen

2016

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

Ghostwriter, UNC1151 and PUSHCHA

Ghostwriter is tracked under several vendor names across the phishing and influence sides of its activity. It maps to one entry among the state-aligned actors we monitor, and its regional targeting overlaps with Russia-linked crews like Gamaredon.

-

-

-

GROUP PROFILE

Credential phishing tied to influence operations

Ghostwriter combines cyber operations with information operations. UNC1151 provides the technical side, credential theft and malware, while the broader Ghostwriter campaign has pushed disinformation narratives hostile to NATO and regional governments.

Our record places its origin as Belarus and ties it to operations against government, media and civil-society targets. Since March 2026 the group intensified Gmail phishing against high-profile individuals in Poland, and it has targeted Ukrainian email portals and Belarusian opposition figures.

The group's recent tradecraft leans on convincing Google and Gmail admin-themed alerts that harvest credentials and 2FA codes, alongside document lures carrying PicassoLoader and commodity RATs.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

-

ATTACK LIFECYCLE

Themed alerts into credential and 2FA theft

The stages below come from Ghostwriter and UNC1151 activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

PicassoLoader and commodity RATs

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

CVES EXPLOITED

Access through phishing, not CVE exploitation

Ghostwriter's recent intrusions in our records rely on credential phishing and document lures rather than on exploiting software vulnerabilities for initial access, so this profile does not list a confirmed exploited-CVE set. Older document chains have used Office exploits such as CVE-2017-11882, but the current activity is credential-harvesting led, so detection should focus on the Gmail-themed phishing and the PicassoLoader document chain.

Ghostwriter

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

Ghostwriter

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

Ghostwriter

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

Ghostwriter

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

Gmail phishing across Poland, Ukraine and Belarus

Recent reporting tracks the 2026 credential-theft operations.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

Ghostwriter

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

Ghostwriter

IOC set, full IP, host and hash history.