Belarusian Hackers Target Yury Hubarevich with Sophisticated Phishing Attack
ID: ca2fce87-5701-5b6b-b6a8-8592c51101d4
STIX ID: report--ca2fce87-5701-5b6b-b6a8-8592c51101d4
Feed Name: ThreatCluster
Threat Score
On 2026-05-29 UNC1151-linked attackers sent a sophisticated AiTM phishing email to Belarusian opposition politician Yury Hubarevich that redirected via a compromised Ukrainian e-commerce site to a BunnyCDN-hosted fake Google sign-in page, streaming usernames, passwords, and real-time 2FA codes to infrastructure at IP 45.194.44.44; the attempt was detected and reported, no account takeover was confirmed, and analysts recommend FIDO2/passkeys and blocking the identified domain and IP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
