/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Cybersecurity firm Mandiant says it has “high confidence” that Belarus is partially responsible for Ghostwriter, a hack-and-leak operation in some EU states

Mandiant says the government is likely to blame for anti-NATO campaigns, and more.  —  The Belarusian government … Source: Mandiant .

ZDNet Charlie Osborne

Context & Ripple Effects

In September, the EU formally blamed Russia and its state hackers for Ghostwriter, a hack-and-leak operation active in member states since 2017. Mandiant's new assessment widens that attribution: it says Belarus shares responsibility for the same operation and its anti-NATO campaigns.

The finding lands on a country with an unusually crowded cyber landscape — Minsk's services are implicated in offensive work abroad, while inside Belarus the opposition Cyber Partisans have been dumping government and police data to undermine Lukashenko. Attribution here is not one actor but a stack of them.

First-order effects

  • EU member states targeted by Ghostwriter must now treat Minsk, not just Moscow, as a source of the anti-NATO influence campaigns, revising threat assessments and any diplomatic responses built on the earlier single-state accusation.

Second-order effects

Third-order effects

  • If major operations keep resolving into multi-state attributions, EU counter-disinformation policy shifts from naming one adversary government to mapping overlapping operator networks — with commercial forensics firms like Mandiant effectively co-authoring the official record.

The trend: State-backed hack-and-leak attribution is moving from single-government accusations toward multi-state operator networks identified by private-sector forensics firms.

Discussion

  • @tadeuszgiczan Tadeusz Giczan on x
    The mailbox of the Polish PM's Head of Chancellery Michał Dworczyk was hacked not by the Russians but by the Belarusian military, report of the US cybersec firm Mandiant says. UNC1151 also conducted multiple attacks against PL, LT, NATO and BY opposition. https://www.mandiant.com…
  • @mandiant @mandiant on x
    Today, the Mandiant Threat Intelligence team shared that it assesses with high confidence that #UNC1151 is linked to the Belarusian govt & that Belarus is likely at least partially responsible for the Ghostwriter IO campaign. Read more on our blog: https://www.mandiant.com/...