UNC1151, also known as Ghostwriter and FrostyNeighbor, targeted Belarusian pro-democracy politician Yury Hubarevich with a phishing email masquerading as a Russian-language Google security alert. The lure redirected the victim through a compromised Ukrainian website to a counterfeit Gmail sign-in page that captured credentials in real time using a background WebSocket connection, a technique that can help attackers intercept session data and bypass SMS- or one-time-password-based MFA protections.
Investigators linked the phishing page to a broader credential-theft infrastructure tied to UNC1151 by pivoting on certificates, server fingerprints, and hosting patterns. The network used domains such as account[.]check-profile[.]digital, hid backend systems behind Bunny CDN and Cloudflare, and exposed additional infrastructure on a Datagear-hosted IP in Poland. Researchers also found phishing pages impersonating Ukrainian services including I.UA, bigmir)net, and META.UA, indicating the operation extended beyond a single spear-phishing attempt and formed part of a wider campaign targeting users in Belarus and Ukraine.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
The same phishing infrastructure was found hosting credential-harvesting pages impersonating Ukrainian portals including I.UA, bigmir)net, and META.UA. This expanded the apparent victim scope beyond a Belarusian political target to Ukrainian users as well.
Investigators pivoted on certificates, server fingerprints, domains, and backend IPs to connect the Hubarevich phishing incident to a wider UNC1151/Ghostwriter infrastructure. The analysis identified additional phishing domains and infrastructure hidden behind Bunny CDN or Cloudflare, supporting attribution to a broader coordinated campaign.
A phishing email impersonating a Google security alert targeted Belarusian pro-democracy politician Yury Hubarevich. The lure redirected through a compromised Ukrainian website to a fake Google login page designed to steal credentials in real time and bypass SMS or OTP-based MFA.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 47 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecensys.com
Open sourceresident.ngo
Open sourcecloud.google.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.