惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
阮一峰的网络日志
阮一峰的网络日志
T
Tailwind CSS Blog
博客园 - 【当耐特】
量子位
博客园 - 叶小钗
有赞技术团队
有赞技术团队
Jina AI
Jina AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - Franky
博客园 - 司徒正美
爱范儿
爱范儿
美团技术团队
小众软件
小众软件
酷 壳 – CoolShell
酷 壳 – CoolShell
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
V
V2EX
罗磊的独立博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Last Week in AI
Last Week in AI
Hugging Face - Blog
Hugging Face - Blog
I
InfoQ
D
DataBreaches.Net
宝玉的分享
宝玉的分享

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! Hackers Use Rokarolla Android Malware to Disable Google Play Protect and Control Devices UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to St...
Tushar Subhra Dutta · 2026-06-17 · via Cyber Security News

A state-linked hacker group known as Ghostwriter has launched a wave of targeted phishing attacks aimed at Gmail users, disguising malicious emails as official security alerts from Google.

The campaign is designed to trick recipients into handing over their login credentials and two-factor authentication codes, effectively bypassing one of the most trusted layers of account security that people rely on today.

The group, also tracked as UNC1151, has a long history of targeting Polish citizens through their inboxes. For several years, their operations focused on users of Polish email services like Onet, Wirtualna Polska, and Interia.

Since March 2026, however, the group shifted its focus entirely to Gmail accounts, running campaigns with high intensity, primarily on weekdays, and new phishing domains have been appearing almost every single day.

Analysts at CERT Polska (CERT.PL), the national cybersecurity incident response team operating within the structures of Poland’s National Research Institute, identified and documented this campaign.

According to a report shared with Cyber Security News (CSN), CERT.PL noted that these attacks consistently target individuals in prominent positions, including politicians, researchers, journalists, public servants, and people connected to these groups through family or social ties.

The group’s reach is deliberately wide. Attackers do not always know the exact owner of the targeted inbox and sometimes attempt to guess a victim’s email address, which can result in phishing messages landing in unrelated inboxes with similar names.

CERT.PL also observed campaigns aimed at specific professions such as translators and court experts, suggesting a high degree of deliberate targeting behind each wave of attacks.

The Belarusian-linked threat group appears driven by intelligence gathering rather than financial gain.

Directly addressed message (Source - Cert.PL)
Directly addressed message (Source – Cert.PL)

Once access to a target’s inbox is secured, attackers search for contact lists, sensitive documents, and linked social media accounts, which can then be taken over as well.

This pattern of follow-on exploitation makes every successful compromise far more damaging than a simple stolen password.

Ghostwriter Hackers Abuse Gmail Admin-Themed Emails

The UNC1151 group reaches potential victims through fraudulent emails designed to imitate official Gmail administrator communications.

These messages are usually sent from Gmail accounts created specifically for this purpose, though compromised accounts with modified display names are occasionally used as well.

The emails are written in Polish without obvious errors and typically warn of suspicious activity, unauthorized logins, or service term violations, pressuring recipients to act quickly under the threat of account suspension or permanent deletion.

Once a target clicks the link inside the email, they are taken to a fake website built to mirror the Gmail login panel exactly. This page captures the victim’s email address and password.

Message sent using BCC mechanism (Source - Cert.PL)
Message sent using BCC mechanism (Source – Cert.PL)

A key development in this campaign, compared to earlier operations targeting Polish email providers, is the ability to also steal two-factor authentication codes.

If a second factor is required, the phishing page presents an additional prompt requesting that code, allowing attackers to intercept both SMS-based codes and those generated by apps like Google Authenticator.

Attackers often target the same accounts repeatedly and sometimes send multiple messages within two days to pile on pressure.

Infrastructure Behind the Campaign

The group dynamically rotates the infrastructure it uses to host phishing pages. Operations have involved dedicated domains registered under TLDs such as .icu, .digital, and .top, as well as subdomains hosted on platforms like Netlify.

Domain names are carefully crafted to align with the message content and the sender address used for delivery.

Ghostwriter also places fake login panels on compromised websites belonging to Polish organizations, doing so without altering the main page to keep the intrusion hidden from both site owners and regular visitors.

CERT.PL strongly advises users to treat any email threatening account deletion or suspension as suspicious until verified. Users should never click links in such messages and should instead go directly to the service by typing its address into the browser.

The report also makes clear that a sender’s display name alone cannot be trusted, and that any email referencing account security issues deserves careful scrutiny before taking any action.

Indicators of Compromise (IoCs):-

The following domains and infrastructure were observed in active use during the Ghostwriter Gmail phishing campaign, as documented by CERT.PL.

TypeIndicatorDescription
Domainmailverify.digitalDedicated phishing domain
Domaincheck-mail-verify.bizDedicated phishing domain
Domainverify-check.digitalDedicated phishing domain
Netlify Subdomainmonitoring-google-konta.netlify.appNetlify-hosted phishing page
Netlify Subdomainkonta-weryfikacja.netlify.appNetlify-hosted phishing page
Netlify Subdomainservice-auth.netlify.appNetlify-hosted phishing page
Phishing Page Path/landing-page / homepageCredential harvesting landing page (phishing flow stage 1)
Phishing Page PathPassword harvesting pagePassword capture stage in phishing flow
Phishing Page Path2FA harvesting pageTwo-factor authentication code capture stage
Sender Addressmailsecurenotify@gmail.comExample sender used in campaign (admin-themed)
Sender Addressmailersupport@gmail.comExample sender used in campaign
Sender Addressmonitoring.konta@gmail.comExample sender used in campaign

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.