---
schema: 1
kind: threat
title: "CERT Polska: UNC1151/Ghostwriter shifts to Gmail with real-time 2FA-relay phishing against officials and public administration"
headline: "CERT-PL: Ghostwriter/UNC1151 now phishes Gmail with a live 2FA-relay panel that defeats TOTP and SMS"
summary: >
  CERT Polska reports that the Belarus-linked UNC1151/Ghostwriter group has, since
  March 2026, run a high-intensity Gmail phishing campaign against political and
  public-life figures, senior officials, researchers, journalists, and public-administration
  and law-enforcement staff. The fake login panel relays the second factor in real time —
  harvesting the password then requesting the TOTP/SMS code for an immediate automated
  login — defeating both app-based and SMS 2FA. Push FIDO2/WebAuthn for exposed EU/CH
  public-sector Gmail identities; TOTP and SMS are not sufficient against this design.
discovered_at: "2026-07-09T04:32:59Z"
event_date: "2026-07-08"
run_id: 2026-07-09T0409Z-intel
priority: high
immediate_action: null
tags: [phishing, nation-state, identity, russia-nexus]
regions: [europe, switzerland, dach]
sectors: [public-sector, defense]
entities: ["campaign:frostyneighbor-2026-05-campaign"]
cves: []
sources:
  - url: "https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/"
    publisher: "CERT Polska (NASK)"
    date: "2026-07-08"
    role: primary
closed_sources: []
evidence:
  - quote: "Since March 2026, however, the group has been running phishing campaigns targeting Gmail users. These campaigns are carried out with high intensity, mainly on weekdays. Notably, they enable the theft of two-factor authentication (2FA) credentials."
    publisher: "CERT Polska"
  - quote: "If a second factor is required, the phishing page displays an additional form requesting the code. This allows attackers to capture both SMS-based codes and those generated by applications such as Google Authenticator."
    publisher: "CERT Polska"
verification: single-source-national-cert
sourcing_note: "Single-source under the national-CERT carve-out: CERT Polska (NASK, Admiralty A) is the discovering and disclosing authority for its own jurisdiction; no independent corroboration required for its own findings."
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Enforce FIDO2/WebAuthn hardware-bound second factors for any staff whose Google/Gmail identity intersects public-administration, law-enforcement or watchlisted-profession status — real-time relay defeats TOTP and SMS OTP."
  - "Hunt mail-gateway logs for Gmail-lookalike sender display names on newly-registered .icu/.digital/.top domains and *.netlify.app subdomains; alert on a login to a user's account from an unfamiliar ASN occurring seconds after that user visits a flagged phishing URL."
migrated_from: null
---

CERT Polska (NASK) reports that **UNC1151/Ghostwriter** — the Belarus-linked cluster that for years phished Polish-provider webmail (Onet, WP, Interia) — has since March 2026 shifted at high, near-daily intensity to **Gmail accounts**, with new phishing domains appearing almost daily ([CERT Polska, 2026-07-08](https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/)). The lure imitates a Gmail security/administrator notice ("suspicious activity", "account may be blocked") written in error-free Polish and sent from purpose-created Gmail accounts or compromised mailboxes with a spoofed display name, frequently via BCC to obscure the target list. Targeting is broad — political and public-life figures, senior officials, researchers, journalists, public-administration and law-enforcement staff, and their family and social contacts — with some campaigns narrowed to specific professional groups such as translators and court experts.

The core technical escalation over prior campaigns is a **real-time second-factor relay**: after harvesting the password, the fake login panel displays a second form requesting the TOTP/SMS code, which the operators feed into an automated login against the real account, defeating both app-based (Google Authenticator) and SMS-based factors ([CERT Polska, 2026-07-08](https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/)). Infrastructure mixes dedicated phishing domains on `.icu`/`.digital`/`.top` TLDs with abuse of `*.netlify.app` subdomains, plus fake panels planted on compromised Polish websites whose main pages are left untouched to avoid tipping off the site owner. The initial lure maps to `T1566.002 Phishing: Spearphishing Link`; the live-relay capture is best described qualitatively (CERT Polska does not name specific AitM tooling).

**Defender takeaway:** this is the same actor cluster tracked as `campaign:frostyneighbor-2026-05-campaign` (Poland/Lithuania/Ukraine), now with a Gmail-specific, 2FA-defeating tradecraft shift directly relevant to any EU/CH government, law-enforcement or public-administration workforce that uses Google identities. The operational consequence is concrete: TOTP and SMS OTP no longer bound the risk for high-value targets — only phishing-resistant, hardware-bound FIDO2/WebAuthn does. The strongest detection signal is not credential entry but the near-simultaneous automated login from an unfamiliar ASN immediately after a user touches a flagged phishing URL.
