CERT Polska warned that the Belarus-linked GhostWriter group, also tracked as UNC1151 and Storm-0257, has intensified phishing against Gmail users in Poland after previously focusing on local providers such as Onet, Wirtualna Polska, and Interia. Since March, the campaign has increasingly targeted people involved in political and public life, including government officials, journalists, researchers, public administration staff, law enforcement personnel, and in many cases their relatives, personal contacts, and other socially connected individuals.
The attackers are sending Polish-language emails masquerading as Gmail security or administrator alerts and directing victims to fake login pages designed to steal usernames, passwords, and two-factor authentication codes, including SMS and authenticator-app codes. CERT Polska said the group deploys new phishing domains and infrastructure almost daily, including attacker-registered domains, abused Netlify subdomains, and fake panels hosted on compromised Polish websites, while repeatedly pressuring the same targets with follow-up messages; successful account access can expose contacts and sensitive documents and enable further compromise of linked services such as social media.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
CERT Polska reported that since March 2026, the Belarus-linked UNC1151/GhostWriter group has expanded and intensified its phishing activity from Polish email providers to personal Gmail accounts in Poland. The campaign targeted politically exposed individuals, journalists, researchers, public administration and law enforcement personnel, as well as their relatives and social contacts.
CERT Polska said that starting in March 2022, UNC1151/GhostWriter began using the Browser-in-the-Browser technique in phishing attacks targeting Polish users. The method displayed counterfeit browser login windows inside webpages, marking an evolution from earlier redirect-based phishing infrastructure.
Google Threat Analysis Group said that in the past two weeks it observed activity from Ghostwriter and other monitored threat actors targeting users in Ukraine and the surrounding region. TAG described the activity as spanning espionage and phishing campaigns and shared the information to raise awareness among high-risk users and the security community.
Mandiant assessed with high confidence that UNC1151 had links to the Belarusian government and that the Ghostwriter campaign aligned with Belarusian government interests. This marked a notable attribution development for the activity cluster before later phishing tradecraft changes were documented.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
7 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourcetherecord.media
Open sourcecert.pl
Open sourcecert.pl
Open sourceblog.google
Open sourcemandiant.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.