logo

Ghostwriter APT Uses Fake Gmail Login Panels to Steal Passwords and 2FA Codes

ID: f754376d-0c2a-5a8e-a099-5131f1316f31

STIX ID: report--f754376d-0c2a-5a8e-a099-5131f1316f31

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Mayura Kathir

...
...

Ghostwriter (UNC1151) has escalated phishing operations by sending professionally worded Polish-language emails that direct targets to fake Gmail login panels hosted on rapidly changing phishing domains and permissive hosting subdomains; these panels harvest passwords and explicitly capture 2FA codes (SMS and app-generated), enabling account takeover. The campaign targets political actors, public officials, journalists, and related contacts, uses techniques such as BCC distribution, domain churn (examples: mailverify.digital, verify-check.digital, monitoring-google-konta.netlify.app), and compromised small sites; CERT Polska recommends phishing-resistant authentication, domain monitoring, and takedown workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.