TA445 is a state-sponsored threat cluster associated with the Ghostwriter activity set and tracked by some researchers as encompassing UNC1151-related operations. It has been linked to phishing campaigns that leveraged compromised email accounts of Ukrainian armed service members to target European government personnel involved in refugee logistics during the Russia-Ukraine war. The actor’s operations are consistent with intelligence collection and influence-supporting objectives aligned with Russian and Belarusian interests. Observed tradecraft includes targeted phishing using macro-enabled Microsoft Excel attachments, silent installation of MSI packages through Windows Installer, and deployment of Lua-based malware such as SunSeed. SunSeed functioned as a downloader that beaconed to actor-controlled infrastructure and was designed to retrieve follow-on payloads. Related activity established persistence through startup shortcuts and used victim host identifiers in command-and-control communications. Reporting also notes that UNC1151, tracked as part of TA445, conducted widespread phishing against private email accounts of Ukrainian armed service members. Attribution for some individual campaigns overlapping this ecosystem has remained tentative, but TA445 is consistently referenced in connection with UNC1151 and Ghostwriter.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
34 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Acteurs de menace # TA488 (state-sponsored) ... TA445 (state-sponsored) ...
Belarus-linked activity cluster associated with hybrid operations (disinformation + cyber). In this reporting, TA445 is discussed as a likely-aligned actor for phishing/credential-harvesting and intelligence collection focused on refugee movement/logistics and NATO/European government targets; however, Proofpoint does not definitively attribute the SunSeed “Asylum Ambuscade” intrusion chain to TA445.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.