Adversary Intelligence — 2026-06-18

Belarus-Linked UNC1151 Launches Gmail Phishing Campaign Targeting Polish Officials and Stealing 2FA Codes

BLUFUNC1151's real-time 2FA interception capability likely will extend to at least one additional NATO or EU member state by year-end 2026, broadening Minsk's access to allied officials' personal communications outside government monitoring.

Since March 2026, UNC1151 has shifted from Polish domestic email services to Gmail, running high-intensity weekday campaigns with new phishing domains appearing nearly every day, according to CERT Polska 12. The group targets politicians, public officials, journalists, and law enforcement personnel, as well as family members and social contacts; in some cases attackers guess at email addresses based on names and affiliations 13. The campaigns use Polish-language emails impersonating Gmail security alerts to route victims to fake login panels that sequentially harvest passwords and then 2FA codes, including SMS tokens and Google Authenticator outputs, before automatically attempting account access 14. CERT Polska documented infrastructure spanning dedicated domains under .icu, .digital, and .top TLDs, Netlify-hosted subdomains, and fake login panels embedded in compromised Polish organization websites 14.

Analysis
UNC1151's shift to Gmail with real-time 2FA interception closes the authentication gap Polish officials depended on, extending collection to personal devices outside government security monitoring. Near-daily domain rotation and documented re-targeting of the same victims after failed logins signal a sustained collection mandate, not opportunistic harvesting. CERT Polska's advisory is the sole primary source; secondary outlets amplify rather than independently report. The group's established cross-border operational pattern nevertheless makes it likely an allied CERT will document UNC1151 targeting in at least one additional NATO or EU member state by year-end 2026. Moderate confidence, constrained by the absence of confirmed cross-border infrastructure linkages from this campaign phase. The near-daily churn and broad address-guessing could instead mark a time-bounded collection window against a discrete intelligence requirement that does not extend beyond Poland, in which case Poland-only defensive measures hold and no allied CERT coordination is triggered.
4 sources
  1. UNC1151/Ghostwriter phishing campaign targeting Gmail accounts - CERT Polska
  2. Belarus-Linked UNC1151 Launches Gmail Phishing Campaign to Steal 2FA Codes - The Cyber Express
  3. Belarus-linked hackers target Gmail accounts of Polish public figures and their families - The Record
  4. Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes - CyberSecurityNews

View in full brief →

UNCLASSIFIED // OPEN SOURCE