UNC1151, also tracked as UAC-0057 and commonly associated with the name Ghostwriter, is a Belarus-linked state-backed threat actor conducting cyberespionage and supporting information operations. Its attribution to Belarus is supported by technical evidence locating operators in Minsk and links to the Belarusian military. UNC1151 provides intrusion-derived access and information for Ghostwriter, an influence campaign active since at least March 2017; the intrusion group and campaign are closely associated but are not strictly interchangeable entities. The actor targets government officials, politicians, military personnel, media figures, dissidents, and private email users, principally in Ukraine, Poland, Lithuania, Latvia, Germany, and Belarus. Its Ukrainian targeting includes the critical energy sector. Operations combine mailbox credential theft, searches for sensitive documents, linked social-media account takeovers, and hack-and-leak activity. Associated influence operations exploit compromised news websites and accounts to distribute fabricated articles, manipulated images, and forged official communications, promoting anti-NATO narratives and political instability in countries neighboring Belarus. UNC1151 uses spear-phishing, impersonated email-provider security notices, Browser-in-the-Browser credential-harvesting pages, malicious Office macros, compiled HTML help documents, PDF-to-HTA delivery chains, and exploitation of WinRAR vulnerability CVE-2023-38831. Its tooling includes modified MicroBackdoor variants with screenshot capability, Cobalt Strike Beacon, and PicassoLoader. Malware chains employ JavaScript and VBScript, obfuscated .NET loaders, in-memory payload execution, and startup-shortcut or registry-based persistence. Backdoor functionality includes system-information collection, remote command execution, reverse shells, screenshots, and file transfer. Activity identified in 2025 also used CAPTCHA-gated macros to obstruct automated analysis and multistage HTA payloads containing data-stealing components.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
CVE-2023-38831 is a vulnerability that enables malicious actors to execute arbitrary code when a user tries to access a harmless file contained within a ZIP archive.
CERT Poland on Friday warned that threat actors are exploiting a Roundcube XSS flaw in a spear-phishing campaign aimed at credential theft. CERT Poland attributed the activity to the Belarusian hacking group UNC1151. Tracked as CVE-2024-42009, the flaw leads to JavaScript code execution when opening an email.
Earlier in 2025, an apparent sender from 193.29.58.37 spoofed the Libyan Navy’s Office of Protocol to send a then-zero-day exploit in Zimbra’s Collaboration Suite, CVE-2025-27915, targeting Brazil’s military.
321 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Suspected state-supported espionage activity targeting the Ukrainian government with a malicious JavaScript file masquerading as a PDF document.
Threat actor mentioned only as part of broader background on the Ukraine cyber threat landscape.
Conducting targeted spear-phishing and credential theft operations against politically sensitive targets in Belarus and Ukraine, including fake Google login pages and phishing pages impersonating Ukrainian portals.
Conducted a spear-phishing campaign against government organizations using compromised accounts to deliver the OYSTERBLUES information stealer.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.