27. Juli 2026 Stand:As of 27. Juli 2026
Täglicher Desinfo-DigestDaily Disinfo Digest · heldin resilience lab

Threat News: Ghostwriter phisht Polens Öffentlichkeit, Brasiliens Warnsystem gekapert, Kaliningrad als Festungs-ErzählungThreat News: Ghostwriter phishes Poland's public sphere, Brazil's alert system hijacked, Kaliningrad as fortress narrative

CERT Polska dokumentiert eine Ausweitung der Belarus-nahen APT-Gruppe Ghostwriter (UNC1151): Gmail-Phishing gegen polnische Politik, Gerichtsgutachter und deren Angehörige. In Brasilien kaperte ein Angreifer das staatliche Katastrophen-Warnsystem und schickte zehn falsche Alarmmeldungen in fünf Bundesstaaten, drei Monate vor den Wahlen im Oktober. EUvsDisinfo seziert in einer zweiteiligen Serie das Kaliningrad-Festungsnarrativ und beschreibt den Informationsraum als Minenfeld für EU-Missionen. Im DACH-Raum legen NZZ und Spiegel die Mechanik der laufenden Landtagswahl-Kampagne offen: täglich neue Fake-Titelseiten, direkte Mails an Redaktionen, Fakes in den Google-Rankings. Dagegen halten: Kanadas Safe Social Media Act, CERT Polska als Frühwarnsensor und die EUvsDisinfo-Wochenreview mit inzwischen 19.724 dokumentierten Fällen.CERT Polska documents an expansion by the Belarus-linked APT group Ghostwriter (UNC1151): Gmail phishing against Polish politics, court experts, and their relatives. In Brazil, an attacker hijacked the national civil defence alert system and pushed ten false alerts into five federal states, three months before October's elections. EUvsDisinfo dissects the Kaliningrad fortress narrative in a two-part series and describes the information space as a minefield for EU missions. In the DACH region, NZZ and Spiegel expose the mechanics of the ongoing state-election campaign: new fake front pages daily, direct emails to newsrooms, fakes in Google rankings. Pushing back: Canada's Safe Social Media Act, CERT Polska as an early-warning sensor, and the EUvsDisinfo weekly review with 19,724 documented cases to date.

3
Neue/eskalierte Threat ActorsNew/escalated Threat Actors
3
Aktive KampagnenActive Campaigns
3
Defending Actors
5–6 Mio.5–6M
Menschen unter Info-BelagerungPeople under info siege
10
Falsche Alerts in BrasilienFalse alerts in Brazil
Kategorie 01 · Threat ActorsCategory 01 · Threat Actors

Neue und eskalierte BedrohungsakteureNew and escalated threat actors

Staatliche und staatsnahe Akteure, die durch neue Operationen, Berichte oder Eskalationen in den Fokus geraten sind.State and state-aligned actors that have come into focus through new operations, reports, or escalations.

Staatsnah · BelarusState-aligned · Belarus

Ghostwriter (UNC1151) weitet Phishing auf Gmail-Konten polnischer Persönlichkeiten ausGhostwriter (UNC1151) expands phishing to Gmail accounts of Polish public figures

CERT Polska berichtet über eine Phishing-Kampagne der Belarus-nahen APT-Gruppe Ghostwriter (UNC1151) gegen Gmail-Konten polnischer Politikerinnen, Politiker und öffentlicher Persönlichkeiten, ausdrücklich auch gegen deren Angehörige sowie gezielt gegen Berufsgruppen wie Gerichtsgutachter und Übersetzer. Die Mails imitieren offizielle Gmail-Administrator-Nachrichten, kommen teils von bereits kompromittierten Konten und sollen Zugangsdaten samt Zwei-Faktor-Codes abgreifen. Bisher zielte die Gruppe auf polnische Anbieter wie Intria, Onet und Wirtualna Polska; der Schwenk zu Gmail markiert eine Ausweitung. Relevant für den DACH-Raum: Ghostwriter steht seit Jahren für die Verbindung von Phishing, Hack-and-Leak und Einflussoperationen in Mitteleuropa.CERT Polska reports a phishing campaign by the Belarus-linked APT group Ghostwriter (UNC1151) against Gmail accounts of Polish politicians and public figures, explicitly including their relatives, and targeting professional groups such as court experts and translators. The emails imitate official Gmail administrator notices, are partly sent from already compromised accounts, and aim to harvest credentials including two-factor codes. The group previously targeted Polish providers such as Intria, Onet, and Wirtualna Polska; the pivot to Gmail marks an expansion. Relevant for the DACH region: Ghostwriter has stood for years for the combination of phishing, hack-and-leak, and influence operations in Central Europe.

Staatlich · RusslandState · Russia

Russische FIMI macht den Informationsraum zum Minenfeld für EU-MissionenRussian FIMI turns the information space into a minefield for EU missions

Eine EUvsDisinfo-Analyse zeichnet nach, wie russische FIMI-Operationen gezielt EU-Missionen und -Operationen der Gemeinsamen Sicherheits- und Verteidigungspolitik (CSDP) ins Visier nehmen. Fallbeispiel Armenien: Nachdem die Wählerschaft bei der Parlamentswahl im Juni 2026 das Mandat von Premierminister Paschinjan erneuert und damit den Kurs engerer EU-Kooperation bestätigt hatte, wurde das Land zur Zielscheibe russischer Manipulationskampagnen. Die Analyse beschreibt ein Muster, das über Armenien hinausweist: Wo die EU zivil oder militärisch präsent ist, wird der umgebende Informationsraum systematisch bearbeitet, um Vertrauen in die Mission, das Gastland und die EU selbst zu zersetzen.An EUvsDisinfo analysis traces how Russian FIMI operations deliberately target EU missions and operations under the Common Security and Defence Policy (CSDP). Case in point, Armenia: after voters renewed Prime Minister Pashinyan's mandate in the June 2026 parliamentary elections, confirming the course of closer EU cooperation, the country became a target of Russian manipulation campaigns. The analysis describes a pattern that points beyond Armenia: wherever the EU is present, civilian or military, the surrounding information space is systematically worked to erode trust in the mission, the host country, and the EU itself.

Staatlich · Russland · OstseeState · Russia · Baltic

Kaliningrad als „westliche Festung": Kreml-Propaganda an der EU-GrenzeKaliningrad as "western fortress": Kremlin propaganda on the EU's border

Eine zweiteilige EUvsDisinfo-Serie von Oksana Akmaeva analysiert, wie der Kreml die Exklave Kaliningrad propagandistisch auflädt. Die Oblast an der Ostsee, zwischen den EU- und NATO-Staaten Litauen und Polen gelegen, ist seit der Vollinvasion der Ukraine politisch hochsensibel. Im offiziellen Diskurs wird sie zunehmend als Russlands „westliche Festung" inszeniert: widerstandsfähig, patriotisch und unter ständigem äußerem Druck. Die Serie arbeitet die Spannung zwischen dieser Erzählung und der Lebensrealität vor Ort heraus. Für die Ostsee-Anrainer und den DACH-Raum ist das Framing relevant, weil es Eskalationsnarrative gegen Litauen und Polen vorbereitet und innenpolitische Mobilisierung mit Außenwirkung verbindet.A two-part EUvsDisinfo series by Oksana Akmaeva analyses how the Kremlin charges the exclave of Kaliningrad with propaganda. The oblast on the Baltic Sea, located between EU and NATO members Lithuania and Poland, has been politically sensitive since the full-scale invasion of Ukraine. Official discourse increasingly stages it as Russia's "western fortress": resilient, patriotic, and under constant external pressure. The series works out the tension between this narrative and lived reality. For the Baltic littoral states and the DACH region the framing matters because it prepares escalation narratives against Lithuania and Poland and couples domestic mobilisation with external effect.

Kategorie 02 · KampagnenCategory 02 · Campaigns

Aktive DesinformationsoperationenActive disinformation operations

Laufende, koordinierte Operationen mit dokumentierten Reichweiten und überprüfbaren Zahlen.Ongoing coordinated operations with documented reach and verifiable figures.

Pro-Kreml · DACH · UpdatePro-Kremlin · DACH · Update

Landtagswahl-Kampagne: täglich neue Fakes, Redaktionen als VerstärkerState-election campaign: new fakes daily, newsrooms as amplifiers

Recherchen von NZZ, Spiegel und dem Researchprojekt Antibot4Navalny legen die Mechanik der laufenden, Russland zugeschriebenen Kampagne gegen die deutschen Landtagswahlen im September offen. Seit Ende Juni bringen die Urheber täglich neue gefälschte Kurzvideos und Titelseiten großer deutscher Medien in Umlauf, mit erfundenen Vorwürfen gegen Politikerinnen und Politiker (von Korruptionsaffären bis zu Deepfake-Pornografie). Auffällige Taktik: Redaktionen werden per E-Mail aktiv auf die Fälschungen hingewiesen, verbunden mit der Bitte um einen „Faktencheck", ein Verstärkungstrick, der aus jeder Richtigstellung zusätzliche Reichweite zieht. Bei mindestens einer betroffenen Person rangiert der Fake-Beitrag prominent in der Google-Suche und erreicht so Wählerinnen und Wähler direkt.Research by NZZ, Spiegel, and the research project Antibot4Navalny exposes the mechanics of the ongoing campaign, attributed to Russia, against Germany's September state elections. Since the end of June, the operators have circulated new faked short videos and front pages of major German media daily, carrying invented allegations against politicians (from corruption affairs to deepfake pornography). Notable tactic: newsrooms are actively alerted to the fakes by email, along with a request for a "fact check", an amplification trick that extracts extra reach from every correction. For at least one person affected, the fake post ranks prominently in Google search, reaching voters directly.

Russland · Besetzte GebieteRussia · Occupied Territories

Informationsbelagerung: 5 bis 6 Millionen Menschen im abgeschotteten RaumInformation siege: 5 to 6 million people in a sealed-off space

EUvsDisinfo rückt die Informationskontrolle in den besetzten Gebieten der Ukraine in den Fokus: Geschätzt 5 bis 6 Millionen Menschen werden dort von ukrainischen Medien abgeschnitten, mit Kreml-Propaganda geflutet und durch Internet-Abschaltungen, Messenger-Sperren und Angst zum Schweigen gebracht. Die Analyse beschreibt das als bewusste Strategie: Gemeinschaften isolieren, Identität auslöschen, Widerspruch unterdrücken und die Lage vor der Außenwelt verbergen. Der Fall zeigt die maximale Ausbaustufe dessen, was Desinformationsarchitekturen anstreben: nicht einzelne Narrative platzieren, sondern den gesamten Informationsraum kontrollieren.EUvsDisinfo puts the spotlight on information control in the occupied territories of Ukraine: an estimated 5 to 6 million people there are cut off from Ukrainian media, flooded with Kremlin propaganda, and silenced through internet shutdowns, messenger bans, and fear. The analysis describes this as a deliberate strategy: isolate communities, erase identity, suppress dissent, and conceal the situation from the outside world. The case shows the maximum build-out stage of what disinformation architectures aim for: not placing individual narratives, but controlling the entire information space.

Wahlen · BrasilienElections · Brazil

Brasiliens Warnsystem gekapert: zehn falsche Alarme in fünf BundesstaatenBrazil's alert system hijacked: ten false alarms across five federal states

Brasiliens Zivilschutz musste sein Katastrophen-Warnsystem vom Netz nehmen, nachdem ein Angreifer die Plattform ausgelöst und Meldungen der höchsten Kategorie „Extreme Alert" verschickt hatte: zehn unautorisierte Alarme auf Mobiltelefone in São Paulo, Mato Grosso do Sul, Rio de Janeiro, Paraná und im Bundesdistrikt. Die Nachricht enthielt das Wort „misantropi4" in Leetspeak, was auf einen Cyber-Aktivisten hindeutet. Control Risks warnt vor dem Präzedenzfall: Systeme, die eine ganze Bevölkerung erreichen, sind ein Hebel, um vor den Wahlen im Oktober 2026 Verwirrung zu stiften und Vertrauen in staatliche Kanäle zu untergraben, auch als Blaupause für böswilligere Akteure.Brazil's civil defence had to take its disaster alert system offline after an attacker triggered the platform and sent notifications of the highest "Extreme Alert" category: ten unauthorised alarms to mobile phones in São Paulo, Mato Grosso do Sul, Rio de Janeiro, Paraná, and the Federal District. The message contained the word "misantropi4" in leetspeak, pointing to a cyber activist. Control Risks warns of the precedent: systems that reach an entire population are a lever for sowing confusion ahead of the October 2026 elections and undermining trust in state channels, including as a blueprint for more malicious actors.

Kategorie 03 · Defending ActorsCategory 03 · Defending Actors

Wer gegensteuertWho is pushing back

Institutionen, Behörden und Netzwerke, die mit Warnungen, Berichten, Rechtsakten oder neuen Frameworks reagieren.Institutions, authorities, and networks responding with alerts, reports, legal acts, or new frameworks.

Gesetzgebung · KanadaLegislation · Canada

Kanada bringt den Safe Social Media Act mit Deepfake-Kennzeichnungspflicht einCanada introduces the Safe Social Media Act with mandatory deepfake labelling

Mit dem Safe Social Media Act (Bill C-34) hat Kanada einen Gesetzentwurf eingebracht, der eine Digital Safety Commission mit Durchgriffsrechten schafft: Sie soll die Kennzeichnung von Deepfakes verbindlich anordnen und Plattform-Verantwortlichkeit durchsetzen können. Damit zieht nach der EU (AI Act Artikel 50, durchsetzbar ab 2. August 2026) eine weitere G7-Jurisdiktion regulatorische Leitplanken für synthetische Inhalte ein. Für die Desinfo-Abwehr zählt vor allem die Signalwirkung: Kennzeichnungspflichten und Plattform-Aufsicht entwickeln sich vom Einzelfall zum internationalen Standard, was die Kosten für Kampagnen mit KI-generiertem Material erhöht.With the Safe Social Media Act (Bill C-34), Canada has introduced a bill creating a Digital Safety Commission with enforcement powers: it is to be able to mandate the labelling of deepfakes and enforce platform accountability. After the EU (AI Act Article 50, enforceable from 2 August 2026), another G7 jurisdiction is thus putting regulatory guardrails around synthetic content. What counts most for counter-disinformation is the signal: labelling duties and platform oversight are evolving from isolated cases into an international standard, raising the cost of campaigns built on AI-generated material.

CERT · PolenCERT · Poland

CERT Polska als Frühwarnsensor: Ghostwriter-Kampagne öffentlich gemachtCERT Polska as early-warning sensor: Ghostwriter campaign made public

Dass die Ghostwriter-Ausweitung überhaupt sichtbar wurde, ist der Arbeit von CERT Polska zu verdanken: Das nationale Computer-Notfallteam dokumentierte die Kampagne, benannte die Zielgruppen und veröffentlichte konkrete Schutzempfehlungen, von Multi-Faktor-Authentifizierung über Credential-Monitoring bis zur Verifikation unerwarteter Anfragen über einen zweiten Kanal. Der Fall zeigt den Wert nationaler CERTs als Frühwarnsensoren an der Schnittstelle von Cybersicherheit und Einflussoperationen: Phishing gegen Politik und Multiplikatoren ist häufig die Vorstufe von Hack-and-Leak-Kampagnen, wie sie Mitteleuropa in Wahljahren wiederholt erlebt hat.That the Ghostwriter expansion became visible at all is thanks to the work of CERT Polska: the national computer emergency response team documented the campaign, named the target groups, and published concrete protective guidance, from multi-factor authentication and credential monitoring to verifying unexpected requests via a second channel. The case shows the value of national CERTs as early-warning sensors at the interface of cyber security and influence operations: phishing against politicians and multipliers is frequently the precursor of hack-and-leak campaigns of the kind Central Europe has repeatedly seen in election years.

Beobachtungsstelle · EUMonitoring · EU

EUvsDisinfo-Review: Atomwaffen-Behauptung, Pipeline-Sabotage, Golf-GarantiemachtEUvsDisinfo review: nuclear weapon claim, pipeline sabotage, Gulf guarantor power

Die aktuelle Disinformation Review von EUvsDisinfo seziert drei frische Kreml-Narrative: Der russische Auslandsgeheimdienst SVR wärmt die alte Behauptung auf, europäische Staaten planten, der Ukraine eine Atomwaffe zu überlassen. FIMI-Kanäle beschuldigen die Ukraine und das Vereinigte Königreich, Pipeline-Sabotage vorzubereiten. Und unbelegte Meldungen behaupten, die Golfstaaten hätten Russland gebeten, Garantiemacht eines Nahost-Friedens zu werden, weil kein anderes Land dies könne. Die Falldatenbank des Europäischen Auswärtigen Dienstes umfasst mit Stand 20. Juli 2026 bereits 19.724 gesammelte und widerlegte Fälle und bleibt damit die wichtigste offene Referenzquelle für pro-russische Desinformationsnarrative.The current EUvsDisinfo Disinformation Review dissects three fresh Kremlin narratives: Russia's foreign intelligence service SVR rehashes the old claim that European states plan to hand Ukraine a nuclear weapon. FIMI channels accuse Ukraine and the United Kingdom of preparing pipeline sabotage. And unsubstantiated reports claim the Gulf states asked Russia to become guarantor of a Middle East peace because no other country could do it. As of 20 July 2026 the case database of the European External Action Service already comprises 19,724 collected and debunked cases, remaining the most important open reference source for pro-Russian disinformation narratives.

QuellenverzeichnisSources · Stand 27.07.2026

Quellen & WeiterführendesSources & Further Reading

← Zurück zum Threat News Feed← Back to Threat News Feed