Actor Profile
Ghostwriter (also tracked as UAC-0057 and UNC1151) is a Belarus-aligned threat actor known for conducting information operations and cyber espionage campaigns. The group is motivated by intelligence collection and influence operations aligned with Belarusian state interests. Ghostwriter has historically targeted government and military entities in Eastern Europe, particularly Ukraine and Poland, using phishing and credential harvesting techniques to support broader strategic objectives.
TTPs (Tactics, Techniques, Procedures)
The current campaign leverages spear-phishing emails (T1566.001) with lures impersonating the Prometheus online learning platform to target Ukrainian government organizations. The phishing infrastructure is designed to harvest credentials (T1589.001) from victims who interact with fraudulent login pages. Initial access is achieved through social engineering (T1598), exploiting the trust associated with legitimate educational platforms used by government personnel. CERT-UA documentation suggests the campaign follows Ghostwriter's established pattern of credential theft for subsequent access and intelligence gathering.
Targets & Patterns
Ghostwriter is targeting Ukrainian government entities, consistent with the actor's strategic focus on Ukraine amid ongoing geopolitical tensions. The use of Prometheus-themed lures is tactically significant, as the platform is widely used for professional development and training within Ukrainian public sector organizations. This targeting pattern reflects the group's intent to compromise government networks for espionage purposes, likely seeking access to sensitive communications, policy documents, and operational intelligence. The focus on government sectors aligns with Belarus-aligned intelligence priorities in the region.
Historical Context
Ghostwriter has been active since at least 2017, with sustained campaigns against Ukrainian, Polish, and Baltic state targets. The group has previously been documented by CERT-UA, Mandiant (as UNC1151), and other threat intelligence providers conducting phishing operations, website defacements, and disinformation campaigns. This Prometheus-themed campaign represents a continuation of Ghostwriter's credential harvesting operations against Ukrainian government infrastructure, consistent with activity patterns observed throughout 2022-2024 during the Russia-Ukraine conflict, where Belarus-aligned actors have supported Russian strategic objectives.
Defensive Recommendations
- Monitor for phishing emails impersonating the Prometheus platform (prometheus.org.ua) and validate sender domains against known legitimate infrastructure
- Implement multi-factor authentication (MFA) for all government personnel to mitigate credential harvesting (T1589.001) even if phishing is successful
- Deploy email security controls to detect and quarantine messages with suspicious links or domains typosquatting legitimate Ukrainian educational platforms
- Conduct user awareness training focused on recognizing Ghostwriter/UAC-0057 phishing tactics, emphasizing verification of login page URLs before credential entry
- Monitor network traffic for connections to known Ghostwriter C2 infrastructure and newly registered domains mimicking Prometheus or other trusted platforms
---
# Geopolitical Context
Geopolitical Context
The campaign attributed to Ghostwriter (also tracked as UAC-0057 and UNC1151) represents a continuation of information operations and cyber espionage activities consistent with Belarusian strategic interests in the context of the ongoing Russia-Ukraine conflict. Belarus has served as a staging ground and logistical hub for Russian military operations since February 2022, and cyber operations aligned with Minsk's posture appear designed to support intelligence collection against Ukrainian government decision-making processes. The use of education-themed lures (Prometheus platform) suggests an attempt to exploit trusted domestic services for credential harvesting or initial access, a technique frequently observed in Eastern European threat landscapes where localized social engineering increases operational success rates.
State Actor Alignment
Ghostwriter has been publicly attributed by multiple Western intelligence agencies and cybersecurity firms to Belarusian state security services, with operational patterns suggesting coordination with or support for Russian strategic objectives. The group's targeting of Ukrainian government entities aligns with Minsk's political alignment with Moscow and its role in facilitating military pressure on Ukraine. While Belarus is subject to coordinated sanctions by the EU, US, and partners due to its support for Russia's invasion, cyber operations attributed to Belarusian actors have received less direct sanctions designation compared to Russian counterparts, though entities and individuals linked to the Lukashenko regime's security apparatus remain under restrictive measures.
Business Impacty pro region
The campaign underscores the persistent cyber threat facing Ukrainian critical government functions, requiring sustained defensive investment and international cyber assistance. For European allies, the activity reinforces concerns about Belarus as a platform for hybrid operations targeting EU neighborhood partners and potentially NATO's eastern flank. The use of education sector infrastructure as an attack vector may prompt Ukrainian authorities to enhance vetting of digital platforms used across government networks. Continued Belarusian cyber activity against Ukraine may also influence EU deliberations on sanctions enforcement and cyber defense cooperation frameworks with Kyiv, particularly regarding intelligence sharing and incident response coordination through mechanisms such as the EU Cyber Rapid Response Teams.
Forecast
If Ghostwriter maintains operational tempo, Ukrainian government entities are likely to face continued credential harvesting and espionage attempts leveraging localized social engineering themes. Should the campaign yield successful intrusions, collected intelligence may be shared with Russian counterparts to support operational planning or information operations. If Western partners increase cyber defense assistance to Ukraine in response, including threat intelligence sharing and detection capabilities, the operational cost for Belarusian actors may rise, potentially forcing adaptation in tactics or targeting. Escalation in Belarus-attributed cyber activity could prompt additional EU or US sanctions designations targeting specific intelligence entities or individuals, though enforcement mechanisms remain constrained by Minsk's geopolitical isolation.
