Ghostwriter APT Uses Fake Gmail Login Panels to Steal Passwords and 2FA Codes
ID: f754376d-0c2a-5a8e-a099-5131f1316f31
STIX ID: report--f754376d-0c2a-5a8e-a099-5131f1316f31
Feed Name: GBHackers
Ghostwriter (UNC1151) has escalated phishing operations by sending professionally worded Polish-language emails that direct targets to fake Gmail login panels hosted on rapidly changing phishing domains and permissive hosting subdomains; these panels harvest passwords and explicitly capture 2FA codes (SMS and app-generated), enabling account takeover. The campaign targets political actors, public officials, journalists, and related contacts, uses techniques such as BCC distribution, domain churn (examples: mailverify.digital, verify-check.digital, monitoring-google-konta.netlify.app), and compromised small sites; CERT Polska recommends phishing-resistant authentication, domain monitoring, and takedown workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
