UNC1151/Ghostwriter phishing campaign targeting Gmail accounts
Essential information
- Published
- 12/06/2026 16:57
- Modified
- 15/06/2026 18:46
- Tags
- 2026-06-12 2fa bypass apt credential-theft ghostwriter gmail phishing poland unc1151
- Related entities
- 1 intrusion sets (apt), 6 others
Description
The UNC1151/Ghostwriter group is conducting high-intensity phishing campaigns targeting Gmail accounts of Polish citizens since March 2026. The campaigns primarily target individuals in political and public life, prominent positions, researchers, journalists, public administration and law enforcement employees, and their associates. Attackers use fraudulent emails impersonating Gmail administrators, claiming suspicious activity or policy violations to pressure victims into verifying their accounts. The phishing infrastructure captures login credentials and two-factor authentication codes through fake login panels. The group utilizes dedicated domains, Netlify subdomains, and compromised websites to host phishing pages. Campaigns run primarily on weekdays with new domains appearing almost daily, demonstrating persistent operational tempo against Polish targets.