216.73.217.22

UNC1151/Ghostwriter phishing campaign targeting Gmail accounts

· Published 12/06/2026 16:57 · Modified 15/06/2026 18:46

Export JSON

Essential information

Published
12/06/2026 16:57
Modified
15/06/2026 18:46
Tags
2026-06-12 2fa bypass apt credential-theft ghostwriter gmail phishing poland unc1151
Related entities
1 intrusion sets (apt), 6 others

Description

The / group is conducting high-intensity campaigns targeting accounts of Polish citizens since March 2026. The campaigns primarily target individuals in political and public life, prominent positions, researchers, journalists, public administration and law enforcement employees, and their associates. Attackers use fraudulent emails impersonating administrators, claiming suspicious activity or policy violations to pressure victims into verifying their accounts. The infrastructure captures login credentials and two-factor authentication codes through fake login panels. The group utilizes dedicated domains, Netlify subdomains, and compromised websites to host pages. Campaigns run primarily on weekdays with new domains appearing almost daily, demonstrating persistent operational tempo against Polish targets.

External references