Google: Russia's Fancy Bear launched phishing campaigns against Ukrainians before the invasion and Belarus' Ghostwriter targeted Ukrainian and Polish militaries
Belarus conducted widespread phishing attacks against members of the Polish military as well as Ukrainian officials …
Washington PostJoseph Menn
Context & Ripple Effects
Google's account places the Ukraine- and Poland-focused activity in a longer record: Secureworks had previously documented Fancy Bear's large-scale Gmail phishing against thousands of users, while Mandiant assessed Belarus as partly responsible for Ghostwriter. The significance is the convergence of two attributed campaigns on military and official targets during the run-up to the invasion.
Related coverage also connects phishing to information operations: Citizen Lab described a phished journalist's emails being altered and leaked in a disinformation campaign. That makes credential theft relevant not only to access, but to the material an operator may later weaponize publicly.
First-order effects
Ukrainian officials and the Ukrainian and Polish militaries face a more clearly attributed phishing threat from Fancy Bear and Ghostwriter, allowing their defenders to prioritize those campaigns over undifferentiated malicious email.
Google's reporting reinforces Ghostwriter's link to Belarus alongside Mandiant's earlier assessment, increasing the operational salience of Belarus-linked activity for Polish and Ukrainian military networks.
Polish military targets broaden the immediate security burden beyond Ukraine, making the campaign a cross-border defense issue rather than a threat confined to Ukrainian government accounts.
Third-order effects
If phishing, account compromise, and influence operations continue to be used together, military cyber defense will increasingly have to treat identity security and information integrity as one operational problem rather than separate domains.
The repeated attribution of Fancy Bear and Ghostwriter points toward a durable pattern of state-linked actors using targeted email access as a low-friction entry point before and alongside overt geopolitical conflict.
The trend: State-linked cyber operations are increasingly combining targeted phishing with influence tactics against military and official audiences across national borders.
NEW: @Google's Threat Analysis Group reports on hacking & DDoS they are seeing in #Ukraine. FancyBear 🇷🇺 : Phishing, large scale Ghostwriter 🇧🇾: Phishing, gov & military focus Mustang Panda 🇨🇳 : Malicious e-mail attachments 1/ By @ShaneHuntley https://blog.google/... https://twit…
New TAG blog outlining what we are seeing with cyberattacks in Ukraine. Details of activity from APT28, GhostWriter, Mustang Panda and DDoS activity. Thanks everyone in TAG, Google and the wider security community working to counter these threats. https://blog.google/...
#Belarus conducted widespread #phishing campaigns against #Ukraine, #Poland, Google says - more proof that the #Russia ally has done more in the war against Ukraine than just staging for Russian troops... GIFT ARTICLE - FREE TO READ: https://www.washingtonpost.com/ ...
Latest from Google's threat intel team: Fancy Bear (🇷🇺): Phishing attacks on Ukrainian media company Ghostwriter (🇧🇾): Phishing attacks on Polish & Ukrainian govt & military officials Mustang Panda (🇨🇳): Ukraine-themed phishing attacks on European orgs https://blog.google/... htt…
APT28 is back at it (again) using malicious blogspot domains to redirect Ukrainian targets to credential harvesting pages. https://blog.google/... This kind of tactic dates back almost five years. https://threatconnect.com/... https://twitter.com/...
Whaaaaat they getting old school, Russia bringing back all the classics! Next thing you know they will be posting disinformation to livejournal. https://twitter.com/...
“We expanded eligibility for Project Shield [https://projectshield.withgoogle.com/ landing], our free protection against DDoS attacks, so that Ukrainian government websites, embassies worldwide and other governments in close proximity to the conflict can stay online[.]”— https://…
As we monitor the cybersecurity landscape in Ukraine, we're continuing our work to counter threat actors in the region. This includes expanding eligibility for Project Shield to protect Ukrainian government websites & sites operated by nearby governments. https://blog.google/... …