惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
S
Securelist
小众软件
小众软件
WordPress大学
WordPress大学
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
The GitHub Blog
The GitHub Blog
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 司徒正美
博客园 - Franky
Hugging Face - Blog
Hugging Face - Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
酷 壳 – CoolShell
酷 壳 – CoolShell
O
OpenAI News
Cloudbric
Cloudbric
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
TaoSecurity Blog
TaoSecurity Blog
MongoDB | Blog
MongoDB | Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
V
V2EX
PCI Perspectives
PCI Perspectives
T
Troy Hunt's Blog
Schneier on Security
Schneier on Security
P
Palo Alto Networks Blog
M
MIT News - Artificial intelligence
V2EX - 技术
V2EX - 技术
阮一峰的网络日志
阮一峰的网络日志
Hacker News - Newest:
Hacker News - Newest: "LLM"
G
Google Developers Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
The Last Watchdog
The Last Watchdog
The Register - Security
The Register - Security
腾讯CDC
N
News and Events Feed by Topic
C
Check Point Blog
爱范儿
爱范儿
T
Tailwind CSS Blog
Webroot Blog
Webroot Blog
P
Proofpoint News Feed
S
Schneier on Security
MyScale Blog
MyScale Blog
N
News | PayPal Newsroom
Recorded Future
Recorded Future
T
Tenable Blog
I
InfoQ
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Microsoft Security Blog
Microsoft Security Blog
Simon Willison's Weblog
Simon Willison's Weblog
Engineering at Meta
Engineering at Meta

The Record from Recorded Future News

US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp Ukraine to use seized crypto from cybercrime group to buy war bonds Russia accuses Apple of ‘political censorship’ after VK apps removed from App Store Turla group adds more malware to Russia’s espionage efforts against Ukraine Russia used social engineering to breach prominent messaging accounts, Ukraine says FCC votes to toughen rules in bid to better protect undersea cables DHS chief says president has met with potential CISA nominee; agency plans to hire 600 Another Russian dairy company reportedly disrupted by cyberattack Ukraine's state postal operator reports app disruption after cyberattack Russia used Cellebrite phone-hacking tool to crack down on dissident after firm cut off country Three ‘cybercrime as a service’ operations undercut by Microsoft, law enforcement German rail services resume after wireless communications outage Indian auto giant Bajaj Auto hit by ransomware incident Five Eyes agencies sound alarm about AI’s threat to cybersecurity Feds seize alleged cyber-scam infrastructure connected to Southeast Asian company Trump directs federal agencies to protect US data from quantum threats Compromise kids online safety bill unveiled by House leaders, with key omission Two Scattered Spider members plead guilty over cyberattack that crippled London transit Tata Electronics confirms cyberattack after alleged Apple, Tesla documents appear online Suspected cyberattack triggers false emergency alerts across parts of Brazil Police raid malware network tied to Russia's Evil Corp hacker group UK's information commissioner resigns over ‘inappropriate humour’ Bulgaria allowed surveillance tech firm to sell products to repressive regimes, report says Australian sugar producer works to restore operations as ransomware group claims attack Hostile states behind three-quarters of attacks on Britain's critical infrastructure, cyber chief warns EU grants Ukraine access to cybersecurity reserve for major attacks Warner warns of CISA cuts, staffing gaps in letter to acting chief GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say India's Telegram ban draws criticism from Durov as company challenges order in court India temporarily blocks Telegram over medical exam cheating fears UK to ban social media access for children under 16 Estonia to quarantine emails sent from Russian .ru domain /maine-turns-off-breach-portal-fake-reports Cyberattack on Russian tech firm Astral disrupts business, government services for week Finland brings charges against cargo ship officers for cutting submarine cables Anthropic says US government forced it to disable cybersecurity AI models Bankruptcy admin approves settlement fund of $47 million for 23andMe data breach victims Major US surveillance program poised to lapse after legislative deadlock South Korea hits Coupang with record $409 million fine over data breach Cyber Force not included in Senate defense policy roadmap British high school sends students home following cyberattack Hacker linked to Void Blizzard faces charges over cyberespionage campaign University of Nottingham confirms cyber incident as Shiny Hunters group claims data theft CISA to require federal agencies to patch some cyber vulnerabilities within 3 days Cyberattack shuts down major Australian sugar mills, disrupting harvest Microsoft ships largest Patch Tuesday on record, with one bug under active attack UK weakens proposed telecoms defenses against Chinese hackers after industry pushback CISA to transform how it assesses cyber vulnerabilities and risks, Andersen says Hackers pose as women seeking romance to spy on Russian soldiers UK gives big tech 3 months to create device controls to block nude images of kids EU unveils tech sovereignty package to cut reliance on US, Chinese suppliers Apple removes Russia’s state-backed messaging app Max from its store Trump considers Palantir exec to lead CISA FTC considers setting aside or modifying $150 million privacy penalty against X Russia seeks to label two anti-Kremlin hacker groups as ‘extremist’ Supreme Court rules FCC fines punishing telecom giants for sharing location data were legal UN food agency investigates breach exposing data of Gaza aid recipients Researcher publishes GitHub token-stealing exploit, blames Microsoft’s disclosure process Five Eyes warn Chinese spies are using job sites to recruit insiders CISA directive for AI executive order to be released this week, Andersen says DHS chief signals efforts to reshape CISA New cyber force would cost up to $11 billion to start, commission says White House unveils pared-back AI executive order Russia claims foreign spy agencies hacked officials' phones Red Hat removes tainted packages after software pipeline compromise Spain arrests suspected hacker for publishing personal data of police, prosecutors and cyber officials Microsoft says it will not pursue security researchers after zero-day backlash Inspector general finds NIST mistakes have made vulnerability database ineffective NSA selects new leads for key cybersecurity posts Afghan finance officials targeted by suspected Pakistani cyberespionage campaign Unknown hacker group targeted Russian maritime universities, diplomats for nearly two years Microsoft calls zero-day releases ‘never justifiable’ as researcher threatens to drop more Cruise giant Carnival confirms data breach affecting nearly 6 million people Canadian man gets 33 years for using social media to coerce US children into sending sexual content Chinese-speaking fraud gang could be stealing millions from 2026 World Cup fans Russia conducting daily attacks on UK 'from seabed to cyberspace,' spy chief warns
Belarus-linked hackers target Gmail accounts of Polish public figures and their families
Daryna Antoniuk · 2026-06-15 · via The Record from Recorded Future News

Poland has warned that a Belarus-linked hacker group has expanded its phishing operations to target personal Gmail accounts belonging to senior public figures and their relatives.

The group, known as GhostWriter, has previously focused on compromising work accounts and email services hosted by Polish email providers. Since March, however, its campaigns have increasingly targeted Gmail users, according to CERT Polska, the country's national computer emergency response team.

The campaign has primarily targeted people involved in political and public life, including government officials, researchers, journalists, public administration employees and law enforcement personnel, as well as family members and social contacts.

CERT Polska said GhostWriter remains one of the most active state-sponsored threat actors monitored by the agency.

"In recent weeks, our team has observed the use of new domains serving phishing pages almost daily," researchers said in a report on Friday.

GhostWriter's phishing campaigns are designed to steal login credentials and two-factor authentication codes, allowing attackers to gain access to victims' email accounts. Once inside, the hackers typically search for contact lists, sensitive documents, and linked online accounts that can be exploited to identify additional targets or take over social media profiles.

Researchers said the attackers do not always know the exact email address of their intended target and sometimes rely on guessing likely Gmail addresses, resulting in phishing messages being sent to unrelated people with similar names. The agency has also observed campaigns targeting specific regions and professional groups, including translators and court experts.

GhostWriter, also tracked as UNC1151 and Storm-0257, has been linked by cybersecurity researchers to Belarusian state intelligence services and has been active against Polish targets since Russia's full-scale invasion of Ukraine.

Beyond credential theft, the group has conducted influence and disinformation operations aimed at undermining Poland's relationships with Ukraine, the United States and NATO while fueling domestic social tensions.

The hackers have also targeted Ukrainian government agencies and military organizations. Earlier this year, researchers said GhostWriter used fake emails disguised as notifications from a popular online learning platform to distribute malware to Ukrainian government officials.

In a separate campaign uncovered by cybersecurity firm SentinelOne last year, the group was seen targeting Belarusian opposition activists.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.