UNC1151 ‘Ghostwriter’ Phishing Campaign Hijacks Gmail Accounts and 2FA Codes
ID: 75142a43-4ab9-5719-8e3d-2f8f71b68e40
STIX ID: report--75142a43-4ab9-5719-8e3d-2f8f71b68e40
Feed Name: securityonline.info
Threat Score
Poland’s CERT warns of an active UNC1151 (Ghostwriter) Gmail phishing campaign, since March 2026, that targets high-profile Polish individuals and their contacts. Attackers use fluent Polish fake Google security alerts, rotating throwaway domains and abused hosting (including netlify.app subdomains) to harvest email credentials and real-time 2FA codes, likely for espionage and influence operations linked to Belarusian state intelligence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
