Actor Profile

UNC1151, also known as Ghostwriter, is a threat actor group attributed by FireEye/Mandiant that has conducted sustained information operations and cyber espionage activities. The group is widely assessed to be linked to Belarusian intelligence services, with some operations coordinated in support of Russian geopolitical interests. UNC1151's primary motivation appears to be intelligence collection and influence operations targeting Eastern European nations, particularly Poland and the Baltic states. The actor is known for combining credential harvesting operations with narrative-driven disinformation campaigns.

TTPs (Tactics, Techniques, Procedures)

The current campaign leverages phishing techniques to compromise Gmail accounts of Polish citizens, consistent with UNC1151's established tradecraft of credential harvesting for initial access (likely T1566 - Phishing, T1078 - Valid Accounts). The group has demonstrated operational evolution over multiple years while maintaining core objectives, suggesting iterative refinement of social engineering lures and delivery mechanisms. Historical UNC1151 operations have employed spearphishing links (T1566.002), credential input prompts on spoofed login pages (T1056.003 - Web Portal Capture), and leveraged compromised accounts for further collection (T1114 - Email Collection) and lateral movement into target networks.

Targets & Patterns

UNC1151/Ghostwriter demonstrates persistent targeting of Polish citizens, reflecting strategic interest in Poland as a NATO member state and key actor in Eastern European security dynamics. The focus on Gmail accounts suggests the group seeks access to personal communications of individuals who may hold intelligence value—potentially government officials, military personnel, journalists, activists, or civil society figures. The multi-year campaign timeline indicates sustained collection requirements rather than opportunistic activity. Poland's geopolitical position, support for Ukraine, and hosting of NATO infrastructure make it a priority target for intelligence services aligned with Russian and Belarusian interests. The targeting pattern aligns with broader Ghostwriter operations observed against Polish, Lithuanian, Latvian, and German entities since at least 2017.

Historical Context

UNC1151/Ghostwriter has been active since at least 2017, with public reporting from Mandiant, Google's Threat Analysis Group, and European cybersecurity agencies documenting sustained campaigns against Poland and Baltic nations. The group gained prominence for coordinated cyber-enabled influence operations that combined website defacements, leaked fabricated documents, and amplification through inauthentic social media personas. Previous campaigns have targeted military personnel, government officials, and politicians with credential phishing operations designed to support both espionage and information manipulation objectives. The current Gmail-focused phishing activity represents a continuation of established patterns, with the group adapting techniques over several years while maintaining consistent strategic targeting of Polish entities. This operational continuity suggests institutional backing and persistent intelligence requirements.

Defensive Recommendations

  • Implement advanced email security controls with URL rewriting and sandboxing to detect phishing links targeting webmail services, particularly Gmail login spoofs
  • Deploy multi-factor authentication (MFA) enforcement for all email accounts, prioritizing hardware tokens or authenticator apps over SMS-based methods to mitigate credential harvesting
  • Conduct targeted security awareness training for Polish government, military, and civil society personnel on UNC1151 phishing tactics, including recognition of spoofed login pages and social engineering lures
  • Monitor for anomalous email account access patterns including impossible travel scenarios, new device logins, and bulk email forwarding rules (T1114.003) that may indicate compromised credentials
  • Establish threat intelligence sharing with Polish CERT and regional partners to rapidly disseminate indicators of compromise (IOCs) associated with UNC1151 phishing infrastructure

---

# Geopolitical Context

Geopolitical Context

UNC1151, tracked by multiple vendors as Ghostwriter, has sustained a multi-year information operation and credential harvesting campaign against Polish targets. The group's activities are consistent with efforts to collect intelligence and enable influence operations in a NATO frontline state. Poland's geographic position, military support to Ukraine, and hosting of allied forces make it a persistent target for espionage and information manipulation. The campaign's longevity and technical evolution suggest institutional backing and strategic prioritization rather than opportunistic cybercrime.

State Actor Alignment

UNC1151/Ghostwriter has been publicly attributed by multiple governments and cybersecurity firms to Belarus, with operational links to Russian intelligence services. The group's targeting patterns align with Belarusian and Russian strategic interests in Eastern Europe. Poland, the European Union, and the United States have imposed cyber-related sanctions on Belarusian entities, though enforcement against persistent APT activity remains challenging. The campaign appears consistent with state-directed espionage and pre-positioning for information operations.

Business Impacty pro region

Sustained targeting of Polish citizens underscores the broader threat environment facing NATO's eastern flank. Poland's role as a logistics hub for military aid to Ukraine and host to rotational allied forces elevates the intelligence value of access to Polish communications. If successful, credential harvesting could enable follow-on operations including disinformation seeding, network reconnaissance, or targeting of government and civil society figures. Other Central and Eastern European states—particularly the Baltics and Romania—face similar persistent campaigns from overlapping threat actors. The use of widely adopted platforms like Gmail complicates defensive efforts and may indicate attempts to evade detection by blending with legitimate traffic.

Forecast

If UNC1151 maintains operational tempo, Polish users of consumer email platforms are likely to face continued phishing attempts with incremental technical refinements. Should geopolitical tensions escalate—particularly around Ukraine or Belarus—the group may intensify operations or shift toward more aggressive information manipulation using compromised accounts. If Western governments increase attribution and sanctions pressure, operational infrastructure may migrate or diversify, but core targeting is unlikely to cease given Poland's strategic significance. Defensive improvements by email providers and user awareness campaigns may reduce success rates, though determined state actors typically adapt to countermeasures over time.