EU Warns Russia Over 'Ghostwriter' Hacking Before German Elections

EU Issues Warning Over Russian Cyber Activities
The European Union has indicated potential action regarding Russia’s alleged participation in harmful cyber activities directed at multiple EU nations.
The "Ghostwriter" Campaign
A campaign known as “Ghostwriter” has been identified as targeting a wide range of individuals within the EU. This includes members of parliaments, government personnel, politicians, journalists, and representatives from civil society.
According to a statement released by the European Council on Friday, the campaign involved unauthorized access to computer systems and personal accounts, resulting in data theft.
Potential EU Response
The collective executive body of the EU, comprised of heads of state, stated that the bloc is contemplating “further steps” in response. However, the specific nature of these actions remains undisclosed.
Nabila Massrali, a spokesperson for the European Council, explained to TechCrunch that the declaration serves as a strong condemnation of the malicious cyber activities, designated as Ghostwriter.
She emphasized that these activities are unacceptable and must cease immediately, as they pose a threat to the EU’s integrity, security, democratic values, and institutions.
The EU urges the Russian Federation to uphold responsible state behavior within the digital realm.
Timing and Context
While the press release did not detail specific incidents, the spokesperson noted the warning coincides with the approaching German elections scheduled for September 26.
German Government Findings
Earlier in the month, Germany reported that the Russia-linked Ghostwriter campaign was combining traditional cyberattacks with disinformation and influence operations.
The aim of this combination was to disseminate false information prior to the upcoming election.
German authorities stated they possessed “reliable information” linking recent cyberattacks – involving phishing emails aimed at obtaining login credentials of lawmakers – to actors within Russia.
Specifically, the attacks were attributed to the Russian military intelligence service, GRU.
Ghostwriter's History and Evolution
The Ghostwriter campaign has been active since 2017, as detailed in a 2020 report by FireEye.
Throughout Europe, it has been involved in anti-NATO disinformation efforts, cyber espionage, and damaging hack-and-leak operations.
A subsequent report from FireEye, released in April of this year, connected the Ghostwriter campaign to UNC1151, a threat actor believed to be supported by the Kremlin.
Expanded Infrastructure and Capabilities
Prevailion, a cybersecurity firm specializing in breach monitoring and adversary intelligence, has discovered that the infrastructure associated with UNC1151 is three times larger than previously estimated.
This suggests that the group’s cyber activities are more extensive and aggressive than initially understood.
Potential for Wider Operations
Karim Hijazi, CEO of Prevailion, indicated earlier this month that UNC1151 is “positioned for a much wider operation, both in Europe and potentially beyond.”
This suggests a heightened risk of future cyber interference.
Related Posts

NHS England Data Breach Confirmed by Tech Provider

Cisco Zero-Day Exploit: Chinese Hackers Targeting Customers

Pornhub Hacked: User Data Extorted by Hacking Group

Google and Apple Release Emergency Security Updates

700credit Data Breach: 5.6 Million Affected
