Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
LLM API Vulnerability Exposes AI Model Reasoning, Poses Data Risk
August 11, 2026
Critical SAP Vulnerabilities Allow Code Injection, Memory Corruption
August 11, 2026
Critical Ivanti Endpoint Manager CVEs Let Remote Attackers Crash Agent Service
August 11, 2026
Home/Threats/Ghostwriter Hackers Abuse Gmail Admin Emails to Steal Credentials, 2FA
Threats

Ghostwriter Hackers Abuse Gmail Admin Emails to Steal Credentials, 2FA

Key Takeaways The state-sponsored Ghostwriter hacking group (also known as UNC1151) has intensified targeted phishing campaigns against Polish Gmail users. The attackers impersonate Google...

David kimber
David kimber
June 17, 2026 5 Min Read
51 0

Key Takeaways

  • The state-sponsored Ghostwriter hacking group (also known as UNC1151) has intensified targeted phishing campaigns against Polish Gmail users.
  • The attackers impersonate Google administration, using convincing emails to steal login credentials and two-factor authentication (2FA) codes.
  • High-profile individuals, including politicians, journalists, and researchers, are primary targets in these intelligence-gathering operations.
  • The campaign leverages dynamically rotated infrastructure, including dedicated phishing domains and compromised Polish websites.

Ghostwriter Shifts Focus to Gmail with Advanced Phishing Tactics

The state-linked threat actor known as Ghostwriter, or UNC1151, has escalated its phishing operations, specifically targeting Gmail users in Poland. These sophisticated attacks leverage meticulously crafted emails that mimic official Google security alerts, aiming to trick recipients into divulging their login credentials and critical two-factor authentication (2FA) codes.

Table Of Content

  • Key Takeaways
  • Ghostwriter Shifts Focus to Gmail with Advanced Phishing Tactics
  • Targeting High-Value Individuals
  • Ghostwriter Hackers Abuse Gmail Admin-Themed Emails
  • Infrastructure Behind the Campaign
  • Indicators of Compromise (IoCs)
  • What You Should Do

Historically, UNC1151 has concentrated its efforts on users of domestic Polish email providers such as Onet, Wirtualna Polska, and Interia. However, since March 2026, the group has entirely redirected its focus to Gmail accounts. This shift has been accompanied by a significant increase in operational intensity, with new phishing domains emerging almost daily, primarily during weekdays. The objective of these campaigns appears to be intelligence gathering rather than financial gain, as observed by analysts.

Targeting High-Value Individuals

CERT Polska (CERT.PL), Poland’s national cybersecurity incident response team, has extensively documented this ongoing campaign. According to a report shared with Cyber Security News (CSN), the attacks consistently target individuals in prominent positions. This includes politicians, academic researchers, journalists, public servants, and individuals connected to these groups through familial or social relationships.

The group employs a broad targeting strategy, sometimes attempting to guess victim email addresses, which occasionally results in phishing messages reaching unintended recipients with similar email patterns. CERT.PL has also noted campaigns specifically aimed at professions like translators and court experts, indicating a highly deliberate and calculated approach behind each wave of attacks.

Upon successful compromise, attackers meticulously search the victim’s inbox for contact lists, sensitive documents, and linked social media accounts, which are then often exploited further. This multi-stage exploitation significantly amplifies the damage beyond mere password theft, as previously highlighted by Google’s threat intelligence analysis on UNC1151.

Ghostwriter Hackers Abuse Gmail Admin-Themed Emails

The UNC1151 group initiates contact with potential victims through fraudulent emails designed to appear as legitimate communications from Gmail administrators. These emails are typically sent from newly created Gmail accounts specifically for the campaign, though compromised accounts with altered display names are also occasionally utilized.

The messages are expertly crafted in Polish, exhibiting no obvious grammatical errors. They commonly feature urgent warnings about suspicious activity, unauthorized login attempts, or violations of service terms. These warnings are designed to pressure recipients into immediate action, often under the threat of account suspension or permanent deletion. For an example of a directly addressed message, refer to the image below (Source – Cert.PL).

Directly addressed message (Source - Cert.PL)
Directly addressed message (Source – Cert.PL)

When a target clicks a link embedded in one of these malicious emails, they are redirected to a deceptive website. This site is meticulously designed to replicate the authentic Gmail login interface, capturing the victim’s email address and password. A significant advancement in this campaign, compared to earlier operations against Polish email providers, is the capability to also harvest two-factor authentication codes. If 2FA is enabled, the phishing page dynamically presents an additional prompt requesting the authentication code, allowing attackers to intercept both SMS-based codes and those generated by authenticator applications like Google Authenticator. The group frequently targets the same accounts repeatedly, sometimes sending multiple phishing messages within a 48-hour window to increase pressure on the victim. An example of a message sent using a BCC mechanism is shown below (Source – Cert.PL).

Message sent using BCC mechanism (Source - Cert.PL)
Message sent using BCC mechanism (Source – Cert.PL)

Infrastructure Behind the Campaign

Ghostwriter employs a highly dynamic infrastructure for hosting its phishing pages. This includes dedicated domains registered under various top-level domains (TLDs) such as .icu, .digital, and .top, as well as subdomains hosted on platforms like Netlify. The domain names are carefully chosen to align with the content of the phishing emails and the sender addresses used for delivery.

Furthermore, Ghostwriter often deploys fake login panels on legitimate, yet compromised, websites belonging to Polish organizations. These panels are typically placed without altering the main page content, ensuring the intrusion remains undetected by both site owners and regular visitors.

CERT.PL strongly advises users to exercise extreme caution with any email that threatens account deletion or suspension. Users should never click links within such messages. Instead, they should navigate directly to the service by manually typing the official address into their browser. The report also emphasizes that a sender’s display name alone is an unreliable indicator of authenticity, and all emails pertaining to account security issues warrant thorough scrutiny before any action is taken.

Indicators of Compromise (IoCs)

The following domains and infrastructure were identified by CERT.PL as actively used during the Ghostwriter Gmail phishing campaign:

Type Indicator Description
Domain mailverify.digital Dedicated phishing domain
Domain check-mail-verify.biz Dedicated phishing domain
Domain verify-check.digital Dedicated phishing domain
Netlify Subdomain monitoring-google-konta.netlify.app Netlify-hosted phishing page
Netlify Subdomain konta-weryfikacja.netlify.app Netlify-hosted phishing page
Netlify Subdomain service-auth.netlify.app Netlify-hosted phishing page
Phishing Page Path /landing-page / homepage Credential harvesting landing page (phishing flow stage 1)
Phishing Page Path Password harvesting page Password capture stage in phishing flow
Phishing Page Path 2FA harvesting page Two-factor authentication code capture stage
Sender Address [email protected] Example sender used in campaign (admin-themed)
Sender Address [email protected] Example sender used in campaign
Sender Address [email protected] Example sender used in campaign

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What You Should Do

  • Verify Sender Authenticity: Always scrutinize the sender’s full email address, not just the display name. Be suspicious of any email claiming to be from Google or a system administrator that asks for credentials.
  • Avoid Clicking Links: Never click on links in suspicious emails, especially those threatening account suspension or deletion. Instead, navigate directly to the service (e.g., Gmail) by typing the official URL into your browser.
  • Enable and Strengthen 2FA: While Ghostwriter can steal 2FA codes, it’s still a critical layer of defense. Prioritize hardware security keys (like FIDO U2F) over SMS-based 2FA, as they are more resistant to phishing.
  • Report Suspicious Emails: Report any suspected phishing emails to Google and your organization’s IT security team. This helps improve detection and protect other users.
  • Educate Yourself and Your Team: Stay informed about the latest phishing techniques. Regular security awareness training is crucial for recognizing and avoiding social engineering attempts.
  • Monitor Account Activity: Regularly review your Google account activity for any unauthorized logins or suspicious actions.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityExploitHackerphishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical Fortinet FortiSandbox Flaws Exploited in Attacks

Next Post

ClickFix Campaign Infects Windows Users With EtherHiding, GULoader

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
US SOCs Combat Alert Fatigue: Strategies for Cybersecurity Noise Reduction
August 11, 2026
Critical Windows PnP Vulnerability Lets Attackers Gain SYSTEM Access
August 11, 2026
ClickFix Users Exposed to Malware via Polygon Blockchain Infrastructure
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us