UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket MFA-Bypass Credential-Phishing Campaign Targets Belarusian Opposition Politician Yury Hubarevich

UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket (TL-2026-1223), also tracked as Ghostwriter Gmail Phishing Campaign, is a high-severity phishing campaign, first published 2026-07-11. It is attributed to UNC1151 (Belarus) with high confidence, affects Google Gmail / Google Account Login, maps to 21 MITRE ATT&CK techniques (T1027, T1036, T1041), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-1223

Threat ID
TL-2026-1223
Also known as
Ghostwriter Gmail Phishing Campaign, WebSocket Relay MFA Bypass Campaign
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-07-11
Last reviewed
2026-07-11
Attribution
UNC1151
Attribution confidence
HIGH
Nation-state nexus
Belarus
Motivation
ESPIONAGE
Target sectors
government administration, civil society, news - media, webmailproviders, defense, telecoms
Target regions
belarus, ukraine, poland, lithuania, latvia, 151 - Eastern Europe
Detection rules
9
Indicators of compromise
27

Malware and tooling in UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket

Malware and tooling: Cobalt Strike Beacon, NJRat, PicassoLoader, Cobalt Strike

UNC1151, tracked as Ghostwriter/FrostyNeighbor/PUSHCHA/Storm-0257/TA445/UAC-0051 and assessed with high confidence to be aligned with Belarusian government interests (with possible Russian coordination), ran Russian-language spear-phishing operations impersonating Google account-security warnings against Belarusian pro-democracy politician Yury Hubarevich and broader Ukrainian webmail-portal users (I.UA, bigmir.net, META.UA). Fake login pages used a real-time WebSocket relay to intercept credentials and OTP/SMS MFA codes synchronously, letting the operator hijack the live session before the victim finished the flow, all staged through compromised Ukrainian websites and obfuscated behind Bunny CDN.

How UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket works

In late April 2026, UNC1151 (publicly tracked as Ghostwriter by Mandiant, FrostyNeighbor by ESET, PUSHCHA/Storm-0257/TA445 by other vendors, and UAC-0051 by CERT-UA) stood up a new wave of credential-phishing infrastructure hosted by Datagear (AS200758) in Poland. The primary campaign, documented by Censys and CyberSecurityNews on 26-29 June 2026, targeted Belarusian opposition politician Yury Hubarevich with a Russian-language email spoofing a Google 'suspicious account activity' warning. Clicking the embedded link routed the victim through a compromised Ukrainian website before landing on a pixel-accurate fake Google login page hosted at account.check-profile.digital. Unlike static credential-harvesting kits, the phishing page's client-side JavaScript streamed every keystroke over a WebSocket (wss://account-emails-verification.cc.cd/ws) to the attacker's backend in real time. This converted an otherwise asynchronous OTP-capture problem (where a one-time SMS/app code expires or is consumed before the attacker can act) into a synchronous adversary-in-the-middle capture: the attacker immediately replayed the captured username, password, and second factor against the real Google service to establish a session while the victim was still staring at a fake 'verification in progress, check back in 24 hours' confirmation screen.

Infrastructure analysis (certificate pivoting off a TLS certificate exposed on 45.194.44.44 before Bunny CDN obfuscation was layered on) surfaced a much broader operation: at least four IPs (45.194.44.44, 45.194.44.46, 45.197.133.104, 111.88.74.246) and nine-plus phishing domains, including direct impersonations of Ukrainian webmail portals I.UA (i-ua.cc.cd) and bigmir.net (bigmir-net.cc.cd), and META.UA (meta-ua.cc.cd) — the same portals UNC1151 targeted in a 2022 campaign. A distinctive fingerprint (HTTP 404 'VPS2 endpoint only for WebSocket' on ports 3001/3002) let researchers pivot to additional related hosts.

The same actor cluster (tracked by ESET as FrostyNeighbor and separately reported by TheHackerNews/SecurityAffairs) has run a parallel, more technically involved campaign against Ukrainian government, defense, and military targets since March 2026: geofenced malicious PDFs impersonating Ukrtelecom serve a benign decoy to any non-Ukrainian IP, while Ukrainian-geolocated victims receive a RAR archive containing a JavaScript-launched PicassoLoader stage. PicassoLoader fingerprints the host (beaconing every 10 minutes) and, following manual operator review, drops a JavaScript-based Cobalt Strike Beacon loader as a third stage — with njRAT also previously observed in the group's toolkit. This is consistent with UNC1151's long operating history: active since at least March 2017, publicly exposed by Mandiant in November 2021 as the group behind the Belarus-aligned 'Ghostwriter' disinformation-and-hack-and-leak operation (assessed with high confidence to align with Belarusian government interests, without ruling out Russian contribution), and previously profiled by CERT Polska, Google TAG, and AttackIQ for repeated credential-phishing and disinformation operations against Ukraine, Poland, Lithuania, and Latvia.

MITRE ATT&CK techniques used in TL-2026-1223

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

Exfiltration

T1041 Exfiltration Over C2 Channel

Credential Access

T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1557 Adversary-in-the-Middle

Collection

T1056 Input Capture

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1573 Encrypted Channel

Discovery

T1082 System Information Discovery; T1614 System Location Discovery

command-and-control

T1090 Proxy

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1588 Obtain Capabilities; T1608 Stage Capabilities

Reconnaissance

T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information

Affected products and versions in UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket

  • Google — Gmail / Google Account Login
    Vulnerable versions: N/A - phishing targets account holders, not software
  • I.UA — I.UA Webmail Portal
    Vulnerable versions: N/A - phishing targets account holders
  • bigmir.net — bigmir.net Webmail Portal
    Vulnerable versions: N/A - phishing targets account holders
  • META.UA — META.UA Webmail Portal
    Vulnerable versions: N/A - phishing targets account holders

Remediation for UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket

Immediate actions

  • Block the documented phishing IPs (45.194.44.44, 45.194.44.46, 45.197.133.104, 111.88.74.246) and domains at email gateway and perimeter firewall
  • Force logout and password reset for any account that interacted with the identified phishing domains
  • Add the four documented TLS certificate SHA256 fingerprints to threat-intel blocklists / TLS inspection deny lists
  • Alert high-risk individuals (opposition politicians, journalists, NGO staff in Belarus/Ukraine/Poland/Lithuania) to the specific 'suspicious account activity' Gmail lure

Workarounds

  • Enforce phishing-resistant MFA (FIDO2/WebAuthn) org-wide for high-risk accounts as an interim mitigation while awaiting hardware key rollout
  • Disable auto-rendering of PDF attachments from unsolicited senders for Ukrainian government/defense mail systems given the geofenced-PDF delivery vector

Longer-term hardening

  • Migrate high-risk users from SMS/app-OTP MFA to FIDO2/WebAuthn hardware security keys, which are resistant to real-time relay/AiTM phishing
  • Deploy DNS/web filtering and browser isolation for high-risk user populations
  • Monitor for WebSocket connections to newly registered lookalike domains as a phishing-kit detection signal
  • Deploy EDR with behavioral detection tuned to PicassoLoader/Cobalt Strike Beacon loader chains for Ukrainian government/defense networks

Weaknesses (CWE) in UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket

CWE-287, CWE-451, CWE-940, CWE-1021

Timeline of UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket

  • UNC1151 activity assessed active since at least March 2017, initially conducting anti-NATO disinformation operations
  • Group compromises legitimate news and media websites to plant fake stories, earning the public name 'Ghostwriter'; post-mid-2020 focus shifts to Belarus's neighbors
  • Mandiant publishes assessment linking UNC1151 to Belarus with high confidence and Ghostwriter campaign to Belarusian government interests
  • UNC1151 previously targets the same Ukrainian webmail portals (I.UA, bigmir.net) later reused as impersonation targets in the 2026 campaign
  • FrostyNeighbor/PUSHCHA campaign against Ukrainian government, defense, and military targets begins, using geofenced Ukrtelecom-themed PDF lures leading to PicassoLoader and Cobalt Strike Beacon
  • New WebSocket-relay phishing infrastructure (Datagear/AS200758, Poland) comes online, including account.check-profile.digital
  • Spear-phishing email impersonating a Google account-security warning is sent to Belarusian pro-democracy politician Yury Hubarevich; Resident.NGO Threat Lab documents the case
  • ESET reports fresh FrostyNeighbor/Ghostwriter activity targeting Ukrainian governmental organizations
  • Security Affairs and TheHackerNews report Ghostwriter's resumed attacks on Ukrainian government targets using geofenced PDF phishing and Cobalt Strike
  • Censys publishes certificate-pivoting research unmasking the WebSocket phishing infrastructure behind Bunny CDN and identifying a multi-domain, multi-IP campaign
  • CyberSecurityNews, GBHackers, and CyberPress publish detailed technical writeups of the real-time WebSocket MFA-bypass mechanism and full IOC set

Sources cited for UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket

More in phishing

Detection coverage for TL-2026-1223

As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1223 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats