Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Ghostwriter

Also known as: UNC1151, TA445, PUSHCHA, Storm-0257, DEV-0257, UAC-0057

Description

Ghostwriter is referred as an 'activity set', with various incidents tied together by overlapping behavioral characteristics and personas, rather than as an actor or group in itself.

Goals & Targeting

Targeted Sectors

Government

AI Analysis

· 1 week ago

Executive Summary

Ghostwriter is identified as a sophisticated cyber threat actor targeting primarily government and political sectors in Eastern Europe and the Middle East. Known for its persistence and advanced tactics, this group has demonstrated a focus on long-term espionage activities through spear-phishing campaigns, supply chain compromises, and zero-day exploits.

Goals & Targeting

Ghostwriter appears to target government institutions and political entities in Eastern Europe, Central Asia, and other regions with significant geopolitical tensions. The group's focus on sectors critical to national security aligns with strategic objectives likely tied to espionage or influence operations. Its victims include ministries, diplomatic entities, and organizations involved in sensitive policy development, suggesting a goal of gathering intelligence for broader strategic advantage.

Enhanced Description

Ghostwriter is classified as an 'activity set' rather than a discrete threat group, characterized by overlapping behavioral patterns and personas across multiple incidents. This designation complicates precise attribution but highlights persistent targeting of government, political, and associated sectors. Ghostwriter has been observed leveraging sophisticated tactics including spear-phishing campaigns, supply chain attacks, and the use of zero-day exploits to gain unauthorized access to networks. The group's operations have resulted in data exfiltration and potential disruption of state functions, indicating a focus on cyber espionage and influence activities. While specific details about its origins and exact objectives remain unclear, Ghostwriter's targeting patterns suggest alignment with geopolitical interests or state-sponsored activity.

Key Capabilities

  • Advanced persistent threat (APT) capabilities
  • Spear-phishing campaigns
  • Supply chain compromise
  • Exploitation of zero-day vulnerabilities
  • Network intrusions and data exfiltration
  • Covert command-and-control infrastructure

MITRE ATT&CK Tactics

Data Exfiltration
Initial Access
Defense Evasion

ATT&CK Techniques

T1059.003 - DLL Injection into explorer.exe
T1055 - Process Injection from .NET
T1566.001 - Account Access Removal of Event Logs

Software / Tooling

Custom malware
Cobalt Strike
Mimikatz
Remote Access Tools (RATs)

Campaigns & Victims

Ghostwriter's campaigns are characterized by long-term persistence and targeted attacks against high-value diplomatic and government targets. The group has been linked to multiple intrusions over several years, suggesting a patient and methodical approach to achieving its objectives. Notable operations include attacks on European ministries and Middle Eastern think tanks, resulting in unauthorized access to sensitive information and potential disruption of national decision-making processes.

IOC Patterns

  • Spear-phishing emails with malicious attachments or links
  • Fileless or reflective malware deployment
  • C2 communication over HTTP/S and DNS channels
  • Use of steganography for data exfiltration

Recommended Actions

  • Implement multi-factor authentication (MFA) for sensitive systems.
  • Enhance network monitoring for signs of APT activity, such as unusual process injection or fileless malware indicators.
  • Conduct regular phishing simulations to improve employee awareness and resilience against spear-phishing attacks.
  • Review supply chain relationships and implement vendor security validation programs to mitigate supply chain risks.
  • Invest in endpoint detection and response (EDR) solutions capable of identifying and neutralizing fileless and reflective malware threats.

Suggested Tags

APT
Cyber Espionage
Government Sector
Unknown Motivation
Eastern Europe

Confidence Assessment

confidence in the attributed behaviors and tactics associated with Ghostwriter remains moderate. While its targeting patterns and TTPs are well-documented, specific details about its organizational structure, ultimate objectives, and long-term strategy are unclear. This uncertainty is compounded by the fact that Ghostwriter is considered an 'activity set' rather than a discrete group, making precise attribution challenging. Additional intelligence on its operational infrastructure and decision-making processes would significantly enhance understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
APT
Cyber Espionage
Government Sector
Unknown Motivation
Eastern Europe

Details

Type
Unknown
Country of Origin
B
Confidence
50%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.