2026-07-09HIGHCERT-PL: Ghostwriter/UNC1151 now phishes Gmail with a live 2FA-relay panel that defeats TOTP and SMS
FrostyNeighbor March–May 2026 campaign
campaign · campaign:frostyneighbor-2026-05-campaign single-sourcesingle-source-national-cert
FrostyNeighbor (Ghostwriter / UNC1151) March–May 2026 campaign against Poland, Lithuania and Ukraine.
Aliases: Ghostwriter, UNC1151
Coverage
4
first 2026-05-08 → last 2026-07-09
Latest activity
2026-07-09
CERT-PL: Ghostwriter/UNC1151 now phishes Gmail with a live 2FA-relay panel that defeats TOTP and SMS
Peak priority
high
2 high · 2 notable
Targets
public-sector
sectors: public-sector, defense, education · regions: europe, switzerland, dach
Sources cited
12
7 hosts
2026-05-084 appearances2026-07-09
Action items (2)
Do-now tasks recorded on the entries about FrostyNeighbor March–May 2026 campaign, newest first. Check the date before acting on an older one.
- Enforce FIDO2/WebAuthn hardware-bound second factors for any staff whose Google/Gmail identity intersects public-administration, law-enforcement or watchlisted-profession status, real-time relay defeats TOTP and SMS OTP.2026-07-09CERT-PL: Ghostwriter/UNC1151 now phishes Gmail with…
- Hunt mail-gateway logs for Gmail-lookalike sender display names on newly-registered .icu/.digital/.top domains and *.netlify.app subdomains; alert on a login to a user's account from an unfamiliar ASN occurring seconds after that user visits a flagged phishing URL.2026-07-09CERT-PL: Ghostwriter/UNC1151 now phishes Gmail with…
Defender insights
What each entry about FrostyNeighbor March–May 2026 campaign tells a defender to do, newest first.
Story timeline
- 2026-07-09CERT Polska: UNC1151/Ghostwriter shifts to Gmail with real-time 2FA-relay phishing against officials and public administration
- 2026-05-23Ghostwriter / UAC-0057 / FrostyNeighbor, CERT-UA documents new OYSTERFRESH → OYSTERBLUES → OYSTERSHUCK implant chain via Prometheus learning-platform lures
- 2026-05-15FrostyNeighbor / Ghostwriter (UNC1151, Belarus state-aligned): ESET documents March–May 2026 campaign targeting Polish, Lithuanian, and Ukrainian government and industrial sectors
- 2026-05-08Pro-Russian hacktivists modify OT pump settings at five Polish water treatment facilities
Hunting pivots
ATT&CK techniques (10 across 7 tactics)
10 techniques observed across 3 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessPhishing · Phishing: Spearphishing Attachment · Phishing: Spearphishing Link
- ExecutionCommand and Scripting Interpreter · Command and Scripting Interpreter: JavaScript
- PersistenceBoot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- Privilege EscalationBoot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- StealthObfuscated Files or Information
- DiscoverySystem Information Discovery
- Command and ControlIngress Tool Transfer · Remote Access Tools
Initial Access TA0001
T1566Phishing×1
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.
Evidence: 2026-05-15/frostyneighbor-ghostwriter-unc1151-belarus-state-aligned-ese · ATT&CK page ↗
T1566.001Phishing: Spearphishing Attachment×1
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
Evidence: 2026-05-15/frostyneighbor-ghostwriter-unc1151-belarus-state-aligned-ese · ATT&CK page ↗
T1566.002Phishing: Spearphishing Link×1
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
Evidence: 2026-07-09/unc1151-ghostwriter-gmail-realtime-2fa-phishing · ATT&CK page ↗
Execution TA0002
T1059Command and Scripting Interpreter×1
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
Evidence: 2026-05-15/frostyneighbor-ghostwriter-unc1151-belarus-state-aligned-ese · ATT&CK page ↗
T1059.007Command and Scripting Interpreter: JavaScript×2
Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.
Evidence: 2026-05-23/ghostwriter-uac-0057-frostyneighbor-cert-ua-documents-new-oy · 2026-05-15/frostyneighbor-ghostwriter-unc1151-belarus-state-aligned-ese · ATT&CK page ↗
Persistence TA0003
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-05-23/ghostwriter-uac-0057-frostyneighbor-cert-ua-documents-new-oy · ATT&CK page ↗
Privilege Escalation TA0004
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-05-23/ghostwriter-uac-0057-frostyneighbor-cert-ua-documents-new-oy · ATT&CK page ↗
Stealth TA0005
T1027Obfuscated Files or Information×2
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Evidence: 2026-05-23/ghostwriter-uac-0057-frostyneighbor-cert-ua-documents-new-oy · 2026-05-15/frostyneighbor-ghostwriter-unc1151-belarus-state-aligned-ese · ATT&CK page ↗
Discovery TA0007
T1082System Information Discovery×1
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.
Evidence: 2026-05-15/frostyneighbor-ghostwriter-unc1151-belarus-state-aligned-ese · ATT&CK page ↗
Command and Control TA0011
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-05-15/frostyneighbor-ghostwriter-unc1151-belarus-state-aligned-ese · ATT&CK page ↗
T1219Remote Access Tools×1
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Evidence: 2026-05-23/ghostwriter-uac-0057-frostyneighbor-cert-ua-documents-new-oy · ATT&CK page ↗
Entries about FrostyNeighbor March–May 2026 campaign (4)
Earlier coverage (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- attack.mitre.org5 (42%)
- thehackernews.com2 (17%)
- abw.gov.pl1 (8%)
- cert.pl1 (8%)
- cisa.gov1 (8%)
- scworld.com1 (8%)
- welivesecurity.com1 (8%)
All cited sources (12)
- abw.gov.plABW, Cybersecurity Alert, Polish Water Sector OT Intrusionhttps://abw.gov.pl/pl/cyberbezpieczenstwo/
- attack.mitre.orgT1027https://attack.mitre.org/techniques/T1027/
- attack.mitre.orgT1059.007https://attack.mitre.org/techniques/T1059/007/
- attack.mitre.orgT1082https://attack.mitre.org/techniques/T1082/
- attack.mitre.orgT1105https://attack.mitre.org/techniques/T1105/
- attack.mitre.orgT1566.001https://attack.mitre.org/techniques/T1566/001/
- cert.plCERT Polska (NASK)https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/
- cisa.govCISA AA24-207A, Russian GRU targeting critical infrastructure (background reference)https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a
- scworld.comSC Worldhttps://www.scworld.com/brief/belarus-linked-ghostwriter-group-targets-ukraine-using-prometheus-learning-platform-lures
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/05/ghostwriter-targets-ukraine-government.html
- thehackernews.comThe Hacker News, 2026-05-14https://thehackernews.com/2026/05/ghostwriter-targets-ukrainian.html
- welivesecurity.comESET WeLiveSecurity, 2026-05-14https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/