Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Ghostwriter Campaign Targets Ukrainian Government and Belarusian Opposition 
News & Analysis Attacks Latest News

Ghostwriter Campaign Targets Ukrainian Government and Belarusian Opposition 

Kirsten DoyleBy Kirsten DoyleFebruary 26, 20253 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Cybersecurity researchers at SentinelLABS have uncovered a new campaign linked to the long-running Ghostwriter operation, targeting Belarusian opposition activists and Ukrainian military and government entities.  

The campaign, which entered its active phase in late 2024, is ongoing, with recent malware samples and command-and-control (C2) activity indicating continued threats. 

A Persistent Espionage Operation 

Ghostwriter, an advanced persistent threat (APT) campaign with ties to Belarusian intelligence, has been active since at least 2016.  

Previously tracked by cybersecurity firms under the names UNC1151 (Mandiant) and UAC-0057 (CERT-UA), the campaign blends information manipulation with cyber intrusions.  

Over the years, it has targeted European countries with phishing attacks and malware-laden documents. 

Its latest iteration follows a familiar playbook, using weaponized Excel documents as lures. The themes of these malicious files indicate a focus on political and military affairs, aligning with previous Ghostwriter activities that targeted Ukraine’s Ministry of Defense. 

Malicious Documents Exploit Political Sensitivities 

SentinelLABS identified multiple weaponized Excel files distributed through phishing emails. One such file, titled “Political Prisoners in Minsk Courts”, was sent from a fraudulent Gmail account and hosted on Google Drive.  

Inside the document lurked an obfuscated VBA macro that, when executed, deployed a malicious payload disguised as an audio driver. The malware used advanced evasion techniques, including self-modifying code and memory obfuscation, to help it fly under the radar.  

Notably, the decoy document aped data that is publicly available through Belarusian human rights entities to add credibility to the attack. Researchers speculate that the timing of this attack—not long before Belarus’s presidential election—is a deliberate attempt to target political opponents. 

Another document, labeled “Anti-Corruption Initiative”, was aimed at Ukrainian government personnel. In this instance, similar techniques were used, and a ConfuserEx-protected .NET-based malware downloader was deployed.  

The malware attempted to retrieve a secondary payload from an attacker-controlled domain, a sign of a multi-stage infection process. 

Evolving Tactics and Infrastructure 

While Ghostwriter’s latest campaign is similar to previous operations in many ways, it introduces new techniques. The malefactors employed: 

  • Multi-layered obfuscation: The use of ConfuserEx and Macropack to protect malicious scripts. 
  • Decoy documents: Convincing fake spreadsheets containing real-world information to lure victims. 
  • Targeted payload delivery: Secondary malware payloads are likely distributed only to specific victims based on geolocation and system profiling. 

      The infrastructure behind the campaign also reveals evolution—SentinelLABS identified multiple command-and-control (C2) servers and observed activity linking the operation to previously known Ghostwriter domains. The use of deceptive top-level domains (TLDs) and apparently legitimate images from public websites is another way the threat actors tried to evade detection. 

      Ongoing Threat and Attribution 

      Considering the sophistication of the malware and the way it targets Belarusian opposition and Ukrainian entities, SentinelLABS attributes this campaign to Ghostwriter with high confidence.  

      The group’s ongoing focus on regional political and military themes suggests alignment with Belarusian state interests. 

      Certain attack components remain under analysis, but the evidence so far indicates an adaptive adversary with deep pockets. Considering the ongoing geopolitical tensions in the region, researchers warn that similar campaigns could escalate in the coming months. 

      Kirsten Doyle
      Kirsten Doyle
      Information Security Buzz News Editor

      Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

      • Kirsten Doyle
        SIG report: AI-generated code is linked to twice the security risk and rising technical debt
      • Kirsten Doyle
        Miasma worm spreads from Red Hat packages to Microsoft repositories
      • Kirsten Doyle
        Dutch police, NCSC take down major botnet
      • Kirsten Doyle
        Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

      The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

      Share. Facebook Twitter LinkedIn Email Copy Link

      Related Posts

      SIG report: AI-generated code is linked to twice the security risk and rising technical debt

      June 11, 20264 Mins Read

      Miasma worm spreads from Red Hat packages to Microsoft repositories

      June 11, 20264 Mins Read

      Zero Trust: Beyond the hype, toward reality

      June 9, 20267 Mins Read
      ISB-Bora-Side-Bar

      No se ha podido establecer conexión. Error 429

       
      ISB-Bora-Side-Bar
      Black ISB Logo

      Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

      X (Twitter) LinkedIn Facebook RSS

      Working With Us

      • About Us
      • Advertise With Us
      • Contact Us

      Write For Us

      • How To Contribute

      The Pages

      • Privacy Policy
      • Cookie Policy
      • AI Policy
      • Terms & Conditions
      • Copyright Notice

      Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

      Type above and press Enter to search. Press Esc to cancel.

      Manage Consent
      To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
      Functional Always active
      The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
      Preferences
      The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
      Statistics
      The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
      Marketing
      The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
      • Manage options
      • Manage services
      • Manage {vendor_count} vendors
      • Read more about these purposes
      View preferences
      • {title}
      • {title}
      • {title}