Cybersecurity firm Mandiant says it has “high confidence” that Belarus is partially responsible for Ghostwriter, a hack-and-leak operation in some EU states
Mandiant says the government is likely to blame for anti-NATO campaigns, and more. — The Belarusian government … Source: Mandiant .
Context & Ripple Effects
In September, the EU formally blamed Russia and its state hackers for Ghostwriter, a hack-and-leak operation active in member states since 2017. Mandiant's new assessment widens that attribution: it says Belarus shares responsibility for the same operation and its anti-NATO campaigns.
The finding lands on a country with an unusually crowded cyber landscape — Minsk's services are implicated in offensive work abroad, while inside Belarus the opposition Cyber Partisans have been dumping government and police data to undermine Lukashenko. Attribution here is not one actor but a stack of them.
First-order effects
- EU member states targeted by Ghostwriter must now treat Minsk, not just Moscow, as a source of the anti-NATO influence campaigns, revising threat assessments and any diplomatic responses built on the earlier single-state accusation.
Second-order effects
- Belarus-linked activity becomes harder to compartmentalize for defenders: researchers later documented MoustachedBouncer intercepting ISP connections to spy on foreign diplomats, meaning embassies in Minsk face both espionage and hack-and-leak pressure from the same direction.
Third-order effects
- If major operations keep resolving into multi-state attributions, EU counter-disinformation policy shifts from naming one adversary government to mapping overlapping operator networks — with commercial forensics firms like Mandiant effectively co-authoring the official record.
The trend: State-backed hack-and-leak attribution is moving from single-government accusations toward multi-state operator networks identified by private-sector forensics firms.