Ghostwriter
Ghostwriter is a campaign that joins hacking to fabrication. Instead of building fake audiences, its operators broke into real news websites and the real social media accounts of politicians, or sent emails dressed up as coming from officials, and used that borrowed credibility to publish invented stories: that NATO was pulling out of Lithuania because of Covid-19, that German soldiers had desecrated a Jewish cemetery in Kaunas, that a NATO vehicle had run over a Lithuanian child. A small cast of invented commentators then wrote the fabrications up as opinion pieces on sites that accept outside contributions. Mandiant, which named the campaign in July 2020, traced it back several years and first found it aimed at Lithuania, Latvia and Poland with anti-NATO themes. After the disputed Belarusian election of August 2020 it turned toward discrediting the Polish and Lithuanian governments and the Belarusian opposition, and in 2021 toward German parliamentarians and a large hack-and-leak affair in Poland. Several fabrications were publicly called out as false by the governments concerned. No public study measures whether any of it changed opinion.
A cyber espionage group tracked by Mandiant as UNC1151, which Mandiant links to the government of Belarus. Germany, Poland and the European Union have instead publicly associated the activity with the Russian state. The attributions differ and have not been publicly reconciled.
Attributed by: Mandiant (FireEye) in reports of July 2020, April 2021 and November 2021; the Polish Internal Security Agency and Military Counterintelligence Service (22 June 2021); the German Federal Foreign Office (6 September 2021); the High Representative on behalf of the European Union (24 September 2021); Meta (February 2022).
Confidence, in their words: Mandiant, July 2020: unknown actors, narratives "aligned with Russian security interests", no attribution. April 2021: "high confidence" that UNC1151 "conducts at least some components" of Ghostwriter, while intelligence gaps "do not allow us to conclusively attribute all aspects". November 2021: "high confidence" that UNC1151 is linked to the Belarusian government and "moderate confidence" that it is linked to the Belarusian military; Mandiant "cannot rule out Russian contributions" but had found no direct evidence of them. Germany: the government has "reliable" findings attributing Ghostwriter to "cyber actors of the Russian state and specifically the Russian military intelligence service GRU". Poland: "credible information" linking UNC1151 to "Russian special services". EU: "Some EU Member States" have "associated" the activities "with the Russian state".
Objective
Mandiant's reading of the content: until mid-2020, to "erode regional support for NATO" in the Baltic states and Poland; afterwards, to undermine confidence in the Polish and Lithuanian governments, create tension between those two countries, and discredit the Belarusian opposition and its foreign supporters. Polish services described the aim as "destabilizing the political situation in Central European countries". The EU declaration speaks of attempts "to undermine democratic institutions and processes, including by enabling disinformation and information manipulation".
Target audiences
- The Lithuanian public, the most frequent early target, on the presence of NATO and in particular German and US troops
- Latvian and Polish publics on the same themes (for example a false claim that Canadian soldiers brought Covid-19 to Latvia)
- Polish voters, through hijacked accounts of politicians; the operations Mandiant tabulated used accounts of governing-party figures, while Polish services reported that those targeted by the underlying email attacks came from across the political spectrum and the media
- The Belarusian domestic audience: Mandiant notes that Ghostwriter narratives critical of neighbouring governments were "featured on Belarusian state television as fact"
- As intrusion targets rather than audiences: members of the German Bundestag and state parliaments, Ukrainian government bodies and, in 2022, Ukrainian military personnel, and Belarusian journalists and opposition members
- English-language readers of alternative news and opinion sites, where the invented commentators published
Timeline
- 2016–2017Earliest operations later tied to the campaign. In February 2017 emails and posts on compromised sites falsely claim German soldiers in Lithuania raped a girl; in June 2017 a fabricated press release and video claim a US bomber hit an apartment building.
- January 2018 – September 2019In January 2018 a compromised Lithuanian news site carries a false story accusing the defence minister of sexual assault; Lithuania's National Cyber Security Centre publishes an analysis of the incident. In September 2019 doctored images and a site impersonating a local Jewish organisation are used to claim German soldiers desecrated a Jewish cemetery in Kaunas.
- January – May 2020A run of Covid-themed fabrications: that Lithuania's first case was a US Army officer, that NATO was withdrawing from Lithuania (a forged letter in the name of the NATO Secretary General), that Canadian troops brought the virus to Latvia, and a fake interview in which a US general disparaged the Polish and Baltic militaries.
- 28 July 2020Mandiant publishes its first report, names the campaign "Ghostwriter", identifies at least 14 invented author personas, and declines to attribute it.
- October 2020 – January 2021After the disputed Belarusian election the focus shifts. Five operations use the hijacked social media accounts of Polish politicians to post inflammatory statements about abortion-rights protesters and compromising personal material.
- March – April 2021German media report credential-theft attempts against German parliamentarians. Mandiant's April update ties UNC1151 to at least part of Ghostwriter with high confidence.
- June 2021Emails from the mailbox of the head of the Polish prime minister's office begin to be published online. On 22 June Polish services state that UNC1151 targeted at least 4,350 Polish email addresses, more than 100 of them used by current or former public officials, and that over 500 users responded to the lures; they call it part of Ghostwriter.
- September 2021Three weeks before the federal election Germany publicly attributes Ghostwriter to the GRU and protests to Moscow (6 September). The EU issues a declaration denouncing the activity and urging Russia to respect norms of state behaviour (24 September).
- 16 November 2021Mandiant assesses with high confidence that UNC1151 is linked to the Belarusian government, citing targeting, technical evidence locating operators in Minsk, and the post-2020 narrative shift. It counts 22 of 24 earlier operations as anti-NATO and 16 of 19 later ones as attacks on the Polish and Lithuanian governments.
- 27–28 February 2022Days after Russia's full-scale invasion of Ukraine, Meta reports Ghostwriter taking over accounts of Ukrainian military figures and public personalities to post videos portraying Ukrainian troops as surrendering.
Channels
- Genuine news websites, altered without their owners' knowledge to carry a fabricated article
- Emails impersonating officials, journalists or institutions, sent to newsrooms and public bodies
- Hijacked social media accounts of real politicians and public figures
- Blogs and sites impersonating military units, experts or community organisations
- Opinion pieces by invented authors on open-contribution and alternative news sites
- Messaging-app channels used to publish stolen correspondence (the Polish leak)
- Belarusian state television, which repeated some narratives
Techniques
The defining feature. The lie was placed inside a source the audience already trusted, a familiar news site or a known politician's own account, so the usual check of asking who is saying this gave the wrong answer.
Forged letters, press releases and quotes were issued in the names of the NATO Secretary General, defence ministers, generals and police forces, and emailed to media as though from official addresses.
Fabricated correspondence was presented as leaked, and in the Polish case stolen emails were released a few at a time over months. VSquare reported that the published emails appeared genuine but that the content of a few attached files had been modified, which is what makes such releases hard to evaluate.
At least 14 invented writers, posing as local journalists and analysts, cited the planted fabrications as their source and gave them a second life in English.
A story moved from a compromised site, to an invented columnist citing that site, to alternative outlets citing the columnist. By the time the original was taken down the copies remained.
Many fabrications alleged crimes by allied soldiers against locals: rape, a child killed by a military vehicle, a bombed apartment block, a desecrated cemetery, troops spreading disease.
Later operations picked existing domestic fault lines, most clearly abortion in Poland in late 2020, and put provocative words in the mouths of real politicians.
Private photographs and correspondence obtained through account intrusions were published to embarrass named individuals.
Public reporting by Mandiant, Meta and the German and Polish governments agrees that the intrusions began with deceptive emails aimed at specific politicians, officials and journalists to obtain their login details.
The first months of the Covid-19 pandemic and the first days of the 2022 invasion each produced a burst of activity keyed to public fear and confusion.
Actors, behaviors, content
Actors. A state-linked intrusion team (UNC1151) assessed to perform at least part of the influence work itself, which is unusual; most known operations separate hackers from propagandists. Which state is disputed. Mandiant also records uncertainty about who wrote the content.
Behaviors. Intrusion in the service of publication: compromised websites, spoofed email, account takeover; followed by amplification through invented authors. Short, discrete operations of a few days each, repeated dozens of times over years.
Content. Wholly fabricated events and quotations attributed to real institutions and people, in local languages and English; later, inflammatory posts from real accounts and stolen private material. Themes tracked the sponsor's interests of the moment: NATO deployments, then neighbouring governments and the Belarusian opposition, then Ukraine.
Did it work? What is actually known
There is no published measurement of persuasion for Ghostwriter: no survey or experimental work, and because much of the content sat on third-party websites there are not even consolidated engagement figures. What the sources support is narrower. Mandiant wrote in 2020 that some incidents and personas "received public attention from researchers, foreign news outlets, or government entities in Lithuania and Poland" while others "remain relatively obscure". Government bodies in Lithuania and Poland publicly flagged individual fabrications as false. Mandiant notes that some narratives were repeated as fact on Belarusian state television, which indicates use by a friendly broadcaster rather than organic spread. The figures that do exist measure intrusion, not belief: Polish services counted at least 4,350 targeted addresses and more than 500 users who responded to lures. The Polish email leak ran for months and was widely covered, yet the investigative outlet VSquare judged its political consequences minimal: no official resigned. Whatever effect it had came from the content of apparently real correspondence, and nobody has quantified any change in opinion. The fair summary is: technically serious, politically irritating, persuasive effect unknown and, for the fabricated stories, probably small.
How it was caught
Individual incidents were caught locally: some drew public responses from government bodies in Lithuania and Poland, and Lithuania's National Cyber Security Centre published incident analyses from 2018. The campaign as a whole was recognised when Mandiant noticed that these separate incidents shared methods, themes and the same small cast of invented authors, and published the pattern in 2020. Attribution came from the intrusion side: Mandiant matched emails and a forged letter used in Ghostwriter operations to material held in its data on UNC1151, then reported technical evidence locating operators in Minsk. German and Polish security services reached their own conclusions from investigations of attacks on their politicians, and Meta identified the 2022 account takeovers on its platforms.
Lessons
- »A trusted website or a verified account can be made to say something its owner never said. When a familiar source publishes something wildly out of character, look for the same report elsewhere and for a statement from the institution named before you share it.
- »Official denials are informative. In these cases the denials were accurate. A sensational claim about soldiers or ministers that no other outlet confirms and the named body flatly denies should be treated as unverified.
- »Your own account is part of the information environment. The politicians whose accounts were hijacked were deceived by ordinary-looking emails; the same precautions that protect a private person (unique passwords, two-step sign-in, suspicion of login links) protect the public from words falsely posted in that person's name.
- »Stolen genuine material needs a different question from forged material: not only "is it real" but "who chose what I am seeing, and what was left out or altered".
- »For defenders: newsrooms and small publishers are security targets, not only reporters of security stories. A site that can be made to carry an article it never wrote lends that article its reputation, so securing the site and correcting visibly when it is abused are part of the defence.
- »For defenders: attribution can legitimately differ between competent bodies, and confidence levels matter. Reporting "Russia" or "Belarus" without the stated confidence and the dissenting assessment misinforms in its own way.
Still contested
- Belarus or Russia. Mandiant attributes UNC1151 to Belarus with high confidence and reports no direct evidence of Russian involvement, noting for example that operations hit Lithuania and Latvia, which border Belarus, but were not found in Estonia. The German government names the GRU; Polish services cite links to Russian special services; the EU says some member states associate the activity with Russia. None of the governments has published its evidence. Mandiant considers collaboration plausible, and the positions may describe different parts of one arrangement.
- Whether the hackers and the writers are the same people. Mandiant ties UNC1151 to "at least some components" of the campaign and flags uncertainty about who produced the content and ran the invented authors.
- Whether everything labelled Ghostwriter is one campaign. The label now covers anti-NATO fabrications, Polish account takeovers, German credential theft and activity in Ukraine. They share an intrusion group, but whether they share tasking and purpose is an inference.
- The Polish leak. The government played down the breach and for months left key questions about it unanswered; VSquare concluded the published emails were genuine with a few modified attachments. How much of the full mailbox was taken, and what was withheld or altered, is not publicly known.
- Effect. Governments have described the activity as a threat to security and democratic processes; the public record contains no evidence either way on whether the fabricated stories moved opinion on NATO deployments.
Sources
- Mandiant (FireEye) Threat Intelligence, "Ghostwriter" Influence Campaign: Unknown Actors Leverage Website Compromises and Fabricated Content to Push Narratives Aligned With Russian Security Interests (28 July 2020)Naming of the campaign, activity since at least March 2017, targets and anti-NATO themes, methods at headline level, the 14 invented personas and the sites they used, the absence of attribution, and the note that some incidents drew attention while others stayed obscure.
- Mandiant, Ghostwriter Update: Cyber Espionage Group UNC1151 Likely Conducts Ghostwriter Influence Activity (April 2021)The table of operations with dates and narratives (2016–2021), the five Polish account-takeover operations, the link between UNC1151 and Ghostwriter with its stated limits, and the targeting of German politicians.
- Mandiant, UNC1151 Assessed with High Confidence to have Links to Belarus, Ghostwriter Campaign Aligned with Belarusian Government Interests (16 November 2021)The Belarus attribution and its confidence levels, the evidence categories, the before-and-after narrative counts, the Estonia observation, the statement on possible Russian contributions, and the Belarusian state television point.
- Council of the EU, Declaration by the High Representative on behalf of the European Union on respect for the EU's democratic processes (24 September 2021)The EU's wording on association with the Russian state, the categories of people targeted, and the link drawn to disinformation.
- German Federal Foreign Office, statements at the government press conference of 6 September 2021 (in German)Germany's attribution of Ghostwriter to the GRU, the targeting of federal and state parliamentarians, and the protest to Russia.
- Government of Poland, Findings of the Internal Security Agency and Military Counterintelligence Service on the hacking attacks (22 June 2021, in Polish)The Polish figures (4,350 addresses, over 100 officials' accounts, over 500 responses), the identification of UNC1151 and Ghostwriter, and the stated link to Russian special services.
- Meta, Updates on Our Security Work in Ukraine (27–28 February 2022)Ghostwriter account takeovers of Ukrainian military and public figures and the surrender-video content after the 2022 invasion.
- VSquare, Behind the hack-and-leak scandal in Poland (investigative report)Independent reporting on the Polish email leak: where it was published, the official response, the assessment that the emails were genuine with a few altered attachments, and the limited political consequences.