Belarus-Linked Ghostwriter Targets Polish Officials via Gmail
UNC1151 phishing campaign steals 2FA codes using fake Google security alerts. CERT Polska reports new domains appearing daily as attackers target government officials and their families.
Poland's national CERT issued a warning about an intensifying phishing campaign by Ghostwriter, a threat actor linked to Belarus, that has shifted focus to personal Gmail accounts of senior government officials and their families. The operation marks a tactical pivot from targeting institutional email to personal accounts that often lack enterprise security controls.
New phishing domains have been appearing almost daily since March, according to CERT Polska.
Campaign Targets and Tactics
The operation—tracked as UNC1151 by Mandiant—has historically focused on compromising work accounts hosted by Polish email providers. Since March 2026, the group shifted entirely to Gmail accounts, running high-intensity campaigns primarily on weekdays.
Targets include individuals in political and public life: government officials, researchers, journalists, public administration employees, and law enforcement personnel. The attackers also pursue family members and social contacts of primary targets, likely seeking secondary access paths or leverage for social engineering.
The phishing messages impersonate official Gmail administrator communications, claiming suspicious activity, unauthorized login attempts, or service term violations. The language creates urgency, with some campaigns sending multiple rapid-succession emails to the same target with decreasing response deadlines.
2FA Credential Theft
What distinguishes this campaign is its ability to capture two-factor authentication codes. The fake login pages harvest not just passwords but also SMS verification codes and authenticator app outputs in real-time, enabling immediate account takeover.
This technique—sometimes called real-time phishing or adversary-in-the-middle phishing—has become standard among sophisticated threat actors. We've seen similar approaches in other nation-state campaigns targeting high-value accounts.
Infrastructure and IOCs
Ghostwriter's phishing infrastructure relies on a mix of dedicated malicious domains and abused legitimate services. CERT Polska's advisory identified common patterns:
Domain TLDs frequently used:
- .icu
- .digital
- .biz
- .top
Legitimate service abuse:
- Netlify subdomains (*.netlify.app)
- Compromised Polish organization websites hosting fake login panels
Example malicious domains:
- mailverify[.]digital
- check-mail-verify[.]biz
- verify-check[.]digital
- monitoring-google-konta[.]netlify.app
- konta-24weryfikacja[.]netlify.app
The attackers distribute phishing messages using both newly created accounts and compromised email accounts as senders, making source-based filtering difficult.
Attribution and Context
UNC1151/Ghostwriter has been linked to Belarusian intelligence services. The group gained prominence during the 2020 Belarusian protests and has since maintained focus on Polish targets, likely reflecting geopolitical tensions between the two countries.
The shift to personal Gmail accounts may indicate that enterprise security improvements have made institutional targets harder to compromise. Personal accounts typically lack advanced threat protection, security key requirements, and monitoring that would trigger alerts on suspicious logins.
Defensive Recommendations
For potential targets:
- Enable hardware security keys as your second factor—they resist real-time phishing attacks that SMS and authenticator apps cannot
- Verify sender domains carefully before clicking any links, especially those claiming account issues
- Access Gmail directly by typing the URL rather than following email links
- Report suspicious messages to incydent.cert.pl and Google's abuse reporting
Organizations with personnel in targeted categories should consider enrolling high-risk users in Google's Advanced Protection Program, which requires hardware keys and applies additional verification to sensitive actions.
The persistence of Ghostwriter's operations—running for months with daily domain registration—suggests well-resourced infrastructure and ongoing operational commitment. Polish officials and those connected to them should assume they remain active targets.
Related Articles
Operation HookedWing: 4-Year Phishing Campaign Hit 500+ Organizations
SOCRadar documents a persistent phishing operation that stole 2,000+ credentials from aviation, energy, and government sectors over four years using GitHub-hosted infrastructure.
May 11, 2026Silver Fox APT Impersonates Indian Tax Officials in Espionage Campaign
CloudSEK identifies Chinese threat group Silver Fox targeting Indian organizations with phishing emails disguised as income tax department communications.
Dec 31, 2025Chinese Hackers Stole US Defense, AI Data for 14 Months Undetected
Google TAG exposes UNC6508 campaign that compromised US and Canadian medical, academic, and military research labs since September 2023 using custom INFINITERED malware.
Jun 16, 2026FBI Dismantles Outsider — AI-Powered Phishing Ring Behind $1.9B
Operation Ghost Hook takedown seizes 9,000 fake websites and $100K in crypto from Chinese phishing-as-a-service ring that weaponized Gemini AI to steal 3.8 million credit cards.
Jun 14, 2026