Ghostwriter Hackers Abuse Gmail Admin Emails to Steal Credentials, 2FA
Key Takeaways The state-sponsored Ghostwriter hacking group (also known as UNC1151) has intensified targeted phishing campaigns against Polish Gmail users. The attackers impersonate Google...
Key Takeaways
- The state-sponsored Ghostwriter hacking group (also known as UNC1151) has intensified targeted phishing campaigns against Polish Gmail users.
- The attackers impersonate Google administration, using convincing emails to steal login credentials and two-factor authentication (2FA) codes.
- High-profile individuals, including politicians, journalists, and researchers, are primary targets in these intelligence-gathering operations.
- The campaign leverages dynamically rotated infrastructure, including dedicated phishing domains and compromised Polish websites.
Ghostwriter Shifts Focus to Gmail with Advanced Phishing Tactics
The state-linked threat actor known as Ghostwriter, or UNC1151, has escalated its phishing operations, specifically targeting Gmail users in Poland. These sophisticated attacks leverage meticulously crafted emails that mimic official Google security alerts, aiming to trick recipients into divulging their login credentials and critical two-factor authentication (2FA) codes.
Table Of Content
Historically, UNC1151 has concentrated its efforts on users of domestic Polish email providers such as Onet, Wirtualna Polska, and Interia. However, since March 2026, the group has entirely redirected its focus to Gmail accounts. This shift has been accompanied by a significant increase in operational intensity, with new phishing domains emerging almost daily, primarily during weekdays. The objective of these campaigns appears to be intelligence gathering rather than financial gain, as observed by analysts.
Targeting High-Value Individuals
CERT Polska (CERT.PL), Poland’s national cybersecurity incident response team, has extensively documented this ongoing campaign. According to a report shared with Cyber Security News (CSN), the attacks consistently target individuals in prominent positions. This includes politicians, academic researchers, journalists, public servants, and individuals connected to these groups through familial or social relationships.
The group employs a broad targeting strategy, sometimes attempting to guess victim email addresses, which occasionally results in phishing messages reaching unintended recipients with similar email patterns. CERT.PL has also noted campaigns specifically aimed at professions like translators and court experts, indicating a highly deliberate and calculated approach behind each wave of attacks.
Upon successful compromise, attackers meticulously search the victim’s inbox for contact lists, sensitive documents, and linked social media accounts, which are then often exploited further. This multi-stage exploitation significantly amplifies the damage beyond mere password theft, as previously highlighted by Google’s threat intelligence analysis on UNC1151.
Ghostwriter Hackers Abuse Gmail Admin-Themed Emails
The UNC1151 group initiates contact with potential victims through fraudulent emails designed to appear as legitimate communications from Gmail administrators. These emails are typically sent from newly created Gmail accounts specifically for the campaign, though compromised accounts with altered display names are also occasionally utilized.
The messages are expertly crafted in Polish, exhibiting no obvious grammatical errors. They commonly feature urgent warnings about suspicious activity, unauthorized login attempts, or violations of service terms. These warnings are designed to pressure recipients into immediate action, often under the threat of account suspension or permanent deletion. For an example of a directly addressed message, refer to the image below (Source – Cert.PL).

When a target clicks a link embedded in one of these malicious emails, they are redirected to a deceptive website. This site is meticulously designed to replicate the authentic Gmail login interface, capturing the victim’s email address and password. A significant advancement in this campaign, compared to earlier operations against Polish email providers, is the capability to also harvest two-factor authentication codes. If 2FA is enabled, the phishing page dynamically presents an additional prompt requesting the authentication code, allowing attackers to intercept both SMS-based codes and those generated by authenticator applications like Google Authenticator. The group frequently targets the same accounts repeatedly, sometimes sending multiple phishing messages within a 48-hour window to increase pressure on the victim. An example of a message sent using a BCC mechanism is shown below (Source – Cert.PL).

Infrastructure Behind the Campaign
Ghostwriter employs a highly dynamic infrastructure for hosting its phishing pages. This includes dedicated domains registered under various top-level domains (TLDs) such as .icu, .digital, and .top, as well as subdomains hosted on platforms like Netlify. The domain names are carefully chosen to align with the content of the phishing emails and the sender addresses used for delivery.
Furthermore, Ghostwriter often deploys fake login panels on legitimate, yet compromised, websites belonging to Polish organizations. These panels are typically placed without altering the main page content, ensuring the intrusion remains undetected by both site owners and regular visitors.
CERT.PL strongly advises users to exercise extreme caution with any email that threatens account deletion or suspension. Users should never click links within such messages. Instead, they should navigate directly to the service by manually typing the official address into their browser. The report also emphasizes that a sender’s display name alone is an unreliable indicator of authenticity, and all emails pertaining to account security issues warrant thorough scrutiny before any action is taken.
Indicators of Compromise (IoCs)
The following domains and infrastructure were identified by CERT.PL as actively used during the Ghostwriter Gmail phishing campaign:
| Type | Indicator | Description |
|---|---|---|
| Domain | mailverify.digital | Dedicated phishing domain |
| Domain | check-mail-verify.biz | Dedicated phishing domain |
| Domain | verify-check.digital | Dedicated phishing domain |
| Netlify Subdomain | monitoring-google-konta.netlify.app | Netlify-hosted phishing page |
| Netlify Subdomain | konta-weryfikacja.netlify.app | Netlify-hosted phishing page |
| Netlify Subdomain | service-auth.netlify.app | Netlify-hosted phishing page |
| Phishing Page Path | /landing-page / homepage | Credential harvesting landing page (phishing flow stage 1) |
| Phishing Page Path | Password harvesting page | Password capture stage in phishing flow |
| Phishing Page Path | 2FA harvesting page | Two-factor authentication code capture stage |
| Sender Address | [email protected] | Example sender used in campaign (admin-themed) |
| Sender Address | [email protected] | Example sender used in campaign |
| Sender Address | [email protected] | Example sender used in campaign |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
What You Should Do
- Verify Sender Authenticity: Always scrutinize the sender’s full email address, not just the display name. Be suspicious of any email claiming to be from Google or a system administrator that asks for credentials.
- Avoid Clicking Links: Never click on links in suspicious emails, especially those threatening account suspension or deletion. Instead, navigate directly to the service (e.g., Gmail) by typing the official URL into your browser.
- Enable and Strengthen 2FA: While Ghostwriter can steal 2FA codes, it’s still a critical layer of defense. Prioritize hardware security keys (like FIDO U2F) over SMS-based 2FA, as they are more resistant to phishing.
- Report Suspicious Emails: Report any suspected phishing emails to Google and your organization’s IT security team. This helps improve detection and protect other users.
- Educate Yourself and Your Team: Stay informed about the latest phishing techniques. Regular security awareness training is crucial for recognizing and avoiding social engineering attempts.
- Monitor Account Activity: Regularly review your Google account activity for any unauthorized logins or suspicious actions.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.