UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket MFA-Bypass Credential-Phishing Campaign Targets Belarusian Opposition Politician Yury Hubarevich — Threadlinqs Intelligence
As of 2026-07-11, UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket MFA-Bypass Credential-Phishing Campaign Targets Belarusian Opposition Politician Yury Hubarevich is a high-severity phishing threat attributed to UNC1151 (Belarus), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1223 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
Attribution: UNC1151 · Belarus · ESPIONAGE
UNC1151, tracked as Ghostwriter/FrostyNeighbor/PUSHCHA/Storm-0257/TA445/UAC-0051 and assessed with high confidence to be aligned with Belarusian government interests (with possible Russian
In late April 2026, UNC1151 (publicly tracked as Ghostwriter by Mandiant, FrostyNeighbor by ESET, PUSHCHA/Storm-0257/TA445 by other vendors, and UAC-0051 by CERT-UA) stood up a new wave of credential-phishing infrastructure hosted by Datagear (AS200758) in Poland. The primary campaign, documented by Censys and CyberSecurityNews on 26-29 June 2026, targeted Belarusian opposition politician Yury Hubarevich with a Russian-language email spoofing a Google 'suspicious account activity' warning. Clicking the embedded link routed the victim through a compromised Ukrainian website before landing on a pixel-accurate fake Google login page hosted at account.check-profile.digital. Unlike static credential-harvesting kits, the phishing page's client-side JavaScript streamed every keystroke over a WebSocket (wss://account-emails-verification.cc.cd/ws) to the attacker's backend in real time. This converted an otherwise asynchronous OTP-capture problem (where a one-time SMS/app code expires or is consumed before the attacker can act) into a synchronous adversary-in-the-middle capture: the attacker immediately replayed the captured username, password, and second factor against the real Google service to establish a session while the victim was still staring at a fake 'verification in progress, check back in 24 hours' confirmation screen.
Infrastructure analysis (certificate pivoting off a TLS certificate exposed on 45.194.44.44 before Bunny CDN obfuscation was layered on) surfaced a much broader operation: at least four IPs (45.194.44.44, 45.194.44.46, 45.197.133.104, 111.88.74.246) and nine-plus phishing domains, including direct impersonations of Ukrainian webmail portals I.UA (i-ua.cc.cd) and bigmir.net (bigmir-net.cc.cd), and META.UA (meta-ua.cc.cd) — the same portals UNC1151 targeted in a 2022 campaign. A distinctive fingerprint (HTTP 404 'VPS2 endpoint only for WebSocket' on ports 3001/3002) let researchers pivot to additional related hosts.
The same actor cluster (tracked by ESET as FrostyNeighbor and separately reported by TheHackerNews/SecurityAffairs) has run a parallel, more technically involved campaign against Ukrainian government, defense, and military targets since March 2026: geofenced malicious PDFs impersonating Ukrtelecom serve a benign decoy to any non-Ukrainian IP, while Ukrainian-geolocated victims receive a RAR archive containing a JavaScript-launched PicassoLoader stage. PicassoLoader fingerprints the host (beaconing every 10 minutes) and, following manual operator review, drops a JavaScript-based Cobalt Strike Beacon loader as a third stage — with njRAT also previously observed in the group's toolkit. This is consistent with UNC1151's long operating history: active since at least March 2017, publicly exposed by Mandiant in November 2021 as the group behind the Belarus-aligned 'Ghostwriter' disinformation-and-hack-and-leak operation (assessed with high confidence to align with Belarusian government interests, without ruling out Russian contribution), and previously profiled by CERT Polska, Google TAG, and AttackIQ for repeated credential-phishing and disinformation operations against Ukraine, Poland, Lithuania, and Latvia.
Weaknesses (CWE)
CWE-287, CWE-451, CWE-940, CWE-1021
Target sectors: government administration, civil society, news - media, webmailproviders, defense, telecoms
Target regions: belarus, ukraine, poland, lithuania, latvia, 151 - Eastern Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1589, T1591, T1583, T1583, T1584, T1588, T1608, T1566, T1566, T1204