2021
Ghostwriter Update: Cyber Espionage Group UNC1151 Likely Conducts Ghostwriter Influence Activity
https://content.fireeye.com/web-assets/rpt-unc1151-ghostwriter-update
2021-03
German Parliament targeted again by Russian state hackers
https://www.bleepingcomputer.com/news/security/german-parliament-targeted-again-by-russian-state-hackers/
2022-01
Ukraine suspects group linked to Belarus intelligence over cyberattack
https://www.reuters.com/world/europe/exclusive-ukraine-suspects-group-linked-belarus-intelligence-over-cyberattack-2022-01-15/
2022-02
Ukraine links Belarusian hackers to phishing targeting its military
https://www.bleepingcomputer.com/news/security/ukraine-links-belarusian-hackers-to-phishing-targeting-its-military/
2022-02
In the past several days, we’ve seen increased targeting of people in Ukraine, including Ukrainian military and public figures
https://about.fb.com/news/2022/02/security-updates-ukraine/
2022-02
Operation “Asylum Ambuscade”
State Actor Uses Compromised Private Ukrainian Military Emails to Target European Governments and Refugee Movement
https://www.proofpoint.com/us/blog/threat-insight/asylum-ambuscade-state-actor-uses-compromised-private-ukrainian-military-emails
https://www.welivesecurity.com/2023/06/08/asylum-ambuscade-crimeware-or-cyberespionage/
2022-02
Ghostwriter/UNC1151, a Belarusian threat actor, has conducted credential phishing campaigns over the past week against Polish and Ukrainian government and military organizations.
https://blog.google/threat-analysis-group/update-threat-landscape-ukraine/
2022-03
GhostWriter APT targets state entities of Ukraine with Cobalt Strike Beacon
https://securityaffairs.co/wordpress/129527/apt/ghostwriter-apt-targets-state-entities-of-ukraine-with-cobalt-strike-beacon.html
2022-03
Ghostwriter, a Belarusian threat actor, recently introduced a new capability into their credential phishing campaigns. In mid-March, a security researcher released a blog post detailing a 'Browser in the Browser' phishing technique.
https://blog.google/threat-analysis-group/tracking-cyber-activity-eastern-europe/
2022-04
Ghostwriter, a Belarusian threat actor, has remained active during the course of the war and recently resumed targeting of Gmail accounts via credential phishing.
https://blog.google/threat-analysis-group/update-on-cyber-activity-in-eastern-europe/
2022-04
Malicious campaigns target government, military and civilian entities in Ukraine, Poland
https://blog.talosintelligence.com/malicious-campaigns-target-entities-in-ukraine-poland/
2024-04
UNC1151 Strikes Again: Unveiling Their Tactics Against Ukraine’s Ministry of Defence
https://cyble.com/blog/unc1151-strikes-again-unveiling-their-tactics-against-ukraines-ministry-of-defence/
2025-01
Ghostwriter | New Campaign Targets Ukrainian Government and Belarusian Opposition
https://www.sentinelone.com/labs/ghostwriter-new-campaign-targets-ukrainian-government-and-belarusian-opposition/