/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google: Russia's Fancy Bear launched phishing campaigns against Ukrainians before the invasion and Belarus' Ghostwriter targeted Ukrainian and Polish militaries

Belarus conducted widespread phishing attacks against members of the Polish military as well as Ukrainian officials …

Washington Post Joseph Menn

Context & Ripple Effects

Google's account places the Ukraine- and Poland-focused activity in a longer record: Secureworks had previously documented Fancy Bear's large-scale Gmail phishing against thousands of users, while Mandiant assessed Belarus as partly responsible for Ghostwriter. The significance is the convergence of two attributed campaigns on military and official targets during the run-up to the invasion.

Related coverage also connects phishing to information operations: Citizen Lab described a phished journalist's emails being altered and leaked in a disinformation campaign. That makes credential theft relevant not only to access, but to the material an operator may later weaponize publicly.

First-order effects

  • Ukrainian officials and the Ukrainian and Polish militaries face a more clearly attributed phishing threat from Fancy Bear and Ghostwriter, allowing their defenders to prioritize those campaigns over undifferentiated malicious email.
  • Google's reporting reinforces Ghostwriter's link to Belarus alongside Mandiant's earlier assessment, increasing the operational salience of Belarus-linked activity for Polish and Ukrainian military networks.

Second-order effects

  • Platforms and security teams supporting Ukrainian personnel gain a stronger basis to connect account-compromise attempts with coordinated influence activity; Meta subsequently reported disrupting Belarus- and Russia-linked operations aimed at Ukrainian military personnel.
  • Polish military targets broaden the immediate security burden beyond Ukraine, making the campaign a cross-border defense issue rather than a threat confined to Ukrainian government accounts.

Third-order effects

  • If phishing, account compromise, and influence operations continue to be used together, military cyber defense will increasingly have to treat identity security and information integrity as one operational problem rather than separate domains.
  • The repeated attribution of Fancy Bear and Ghostwriter points toward a durable pattern of state-linked actors using targeted email access as a low-friction entry point before and alongside overt geopolitical conflict.

The trend: State-linked cyber operations are increasingly combining targeted phishing with influence tactics against military and official audiences across national borders.

Discussion

  • @jsrailton John Scott-Railton on x
    NEW: @Google's Threat Analysis Group reports on hacking & DDoS they are seeing in #Ukraine. FancyBear 🇷🇺 : Phishing, large scale Ghostwriter 🇧🇾: Phishing, gov & military focus Mustang Panda 🇨🇳 : Malicious e-mail attachments 1/ By @ShaneHuntley https://blog.google/... https://twit…
  • @shanehuntley Shane Huntley on x
    New TAG blog outlining what we are seeing with cyberattacks in Ukraine. Details of activity from APT28, GhostWriter, Mustang Panda and DDoS activity. Thanks everyone in TAG, Google and the wider security community working to counter these threats. https://blog.google/...
  • @iam_sysop @iam_sysop on x
    #Belarus conducted widespread #phishing campaigns against #Ukraine, #Poland, Google says - more proof that the #Russia ally has done more in the war against Ukraine than just staging for Russian troops... GIFT ARTICLE - FREE TO READ: https://www.washingtonpost.com/ ...
  • @ericgeller Eric Geller on x
    Latest from Google's threat intel team: Fancy Bear (🇷🇺): Phishing attacks on Ukrainian media company Ghostwriter (🇧🇾): Phishing attacks on Polish & Ukrainian govt & military officials Mustang Panda (🇨🇳): Ukraine-themed phishing attacks on European orgs https://blog.google/... htt…
  • @razhael Raphael Satter on x
    APT28 is back at it (again) using malicious blogspot domains to redirect Ukrainian targets to credential harvesting pages. https://blog.google/... This kind of tactic dates back almost five years. https://threatconnect.com/... https://twitter.com/...
  • @josh_emerson Josh Russell on x
    Whaaaaat they getting old school, Russia bringing back all the classics! Next thing you know they will be posting disinformation to livejournal. https://twitter.com/...
  • @tomayac Thomas Steiner on x
    “We expanded eligibility for Project Shield [https://projectshield.withgoogle.com/ landing], our free protection against DDoS attacks, so that Ukrainian government websites, embassies worldwide and other governments in close proximity to the conflict can stay online[.]”— https://…
  • @googleeurope @googleeurope on x
    As we monitor the cybersecurity landscape in Ukraine, we're continuing our work to counter threat actors in the region. This includes expanding eligibility for Project Shield to protect Ukrainian government websites & sites operated by nearby governments. https://blog.google/... …