‘Ghostwriter’ Looks Like a Purely Russian Op—Except It’s Not
For at least four years, the hacking and disinformation group known has Ghostwriter has plagued countries in Eastern Europe and the Baltics. Given its methods—and its anti-NATO and anti-US messages—the widely held assumption has been that Ghostwriter is yet another Kremlin-led campaign. The European Union even declared at the end of September that some member states have “associated” Ghostwriter “with the Russian state.” As it turns out, that’s not quite right. According to the threat intelligence firm Mandiant, Ghostwriter’s hackers work for Belarus.
Mandiant first took a close look at Ghostwriter in July 2020. The group was then primarily known for creating and distributing fake news articles and even hacking real news sites to post misleading content. By April 2021, Mandiant attributed broader activity to Ghostwriter, including operations to compromise the social media accounts of government officials to spread misinformation and efforts to target politicians with hacking and leaking operations. The group has long focused on undermining NATO’s role in Eastern Europe, and has increasingly turned to stoking political divides or instability in Poland, Ukraine, Lithuania, Latvia, and Germany.
At the Cyberwarcon conference in Washington, DC, on Tuesday, Mandiant analysts Ben Read and Gabby Roncone are presenting evidence of Ghostwriter’s ties to Belarus.
“The credential theft activity targeting Eastern Europe and anti-NATO information operations both lined up with what we’ve seen Russia do in the past,” Read told WIRED ahead of the conference. Despite those familiar tactics, techniques, and procedures, Mandiant didn’t make an attribution to Moscow at the time, because they hadn’t seen specific digital links.
After Belarus’ controversial elections in August 2020, longtime president Alexander Lukashenko retained power amid accusations that opposition leader Sviatlana Tsikhanouskaya had actually won. The US denounced the election, and many of Belarus’ neighbors, including Poland, made it clear that they support the Belarusian opposition. During this time, Mandiant observed a notable change in Ghostwriter’s campaigns.
“We saw a shift to a lot more focus on Belarus-specific issues—targeting Belarusian dissidents, Belarusians in the media, things that really look like they’re conducted in support of the Belarusian government,” Read said. “And then we also stumbled upon technical details that make us think the operators are located in Minsk and some others that hint at the Belarusian military. That gets us to the point now where we’re confident in saying that Ghostwriter has a link to Belarus.”
Shane Huntley, who leads Google’s Threat Analysis Group, says that the Mandiant research fits with TAG’s own findings. “Their report is consistent with what we have observed,” he told WIRED.
As the group’s activity hinted more and more at a specifically Belarusian agenda over the summer, Mandiant worked to untangle who was really behind the campaigns. Since last year’s election, 16 of 19 Ghostwriter disinformation operations focused on narratives that disparage the Lithuanian and Polish governments, neighbors of Belarus. Two focused negatively on NATO and one criticized the EU.
A Ghostwriter operation in August focused on Poland and Lithuania pushed a false narrative accusing migrants of committing crimes. Long-simmering tensions between Poland and Belarus have escalated dramatically in recent weeks with the border as a flashpoint. Other recent operations have alleged accidents at Lithuania’s nuclear power plants, perhaps because Lithuania has long opposed the proximity of Belarus’ Astravyets nuclear plant to its border. State television in Belarus has picked up Ghostwriter misinformation narratives and repeated them, though it’s unclear whether this was the result of specific coordination or just part of a general feedback loop of Belarusian pro-government propaganda. Read also points out that Ghostwriter has not focused on Estonia—the one Baltic state that doesn’t border Belarus.