UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket MFA-Bypass Credential-Phishing Campaign Targets Belarusian Opposition Politician Yury Hubarevich
UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket (TL-2026-1223), also tracked as Ghostwriter Gmail Phishing Campaign, is a high-severity phishing campaign, first published 2026-07-11. It is attributed to UNC1151 (Belarus) with high confidence, affects Google Gmail / Google Account Login, maps to 21 MITRE ATT&CK techniques (T1027, T1036, T1041), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-1223
- Threat ID
- TL-2026-1223
- Also known as
- Ghostwriter Gmail Phishing Campaign, WebSocket Relay MFA Bypass Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-07-11
- Last reviewed
- 2026-07-11
- Attribution
- UNC1151
- Attribution confidence
- HIGH
- Nation-state nexus
- Belarus
- Motivation
- ESPIONAGE
- Target sectors
- government administration, civil society, news - media, webmailproviders, defense, telecoms
- Target regions
- belarus, ukraine, poland, lithuania, latvia, 151 - Eastern Europe
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket
Malware and tooling: Cobalt Strike Beacon, NJRat, PicassoLoader, Cobalt Strike
UNC1151, tracked as Ghostwriter/FrostyNeighbor/PUSHCHA/Storm-0257/TA445/UAC-0051 and assessed with high confidence to be aligned with Belarusian government interests (with possible Russian coordination), ran Russian-language spear-phishing operations impersonating Google account-security warnings against Belarusian pro-democracy politician Yury Hubarevich and broader Ukrainian webmail-portal users (I.UA, bigmir.net, META.UA). Fake login pages used a real-time WebSocket relay to intercept credentials and OTP/SMS MFA codes synchronously, letting the operator hijack the live session before the victim finished the flow, all staged through compromised Ukrainian websites and obfuscated behind Bunny CDN.
How UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket works
In late April 2026, UNC1151 (publicly tracked as Ghostwriter by Mandiant, FrostyNeighbor by ESET, PUSHCHA/Storm-0257/TA445 by other vendors, and UAC-0051 by CERT-UA) stood up a new wave of credential-phishing infrastructure hosted by Datagear (AS200758) in Poland. The primary campaign, documented by Censys and CyberSecurityNews on 26-29 June 2026, targeted Belarusian opposition politician Yury Hubarevich with a Russian-language email spoofing a Google 'suspicious account activity' warning. Clicking the embedded link routed the victim through a compromised Ukrainian website before landing on a pixel-accurate fake Google login page hosted at account.check-profile.digital. Unlike static credential-harvesting kits, the phishing page's client-side JavaScript streamed every keystroke over a WebSocket (wss://account-emails-verification.cc.cd/ws) to the attacker's backend in real time. This converted an otherwise asynchronous OTP-capture problem (where a one-time SMS/app code expires or is consumed before the attacker can act) into a synchronous adversary-in-the-middle capture: the attacker immediately replayed the captured username, password, and second factor against the real Google service to establish a session while the victim was still staring at a fake 'verification in progress, check back in 24 hours' confirmation screen.
Infrastructure analysis (certificate pivoting off a TLS certificate exposed on 45.194.44.44 before Bunny CDN obfuscation was layered on) surfaced a much broader operation: at least four IPs (45.194.44.44, 45.194.44.46, 45.197.133.104, 111.88.74.246) and nine-plus phishing domains, including direct impersonations of Ukrainian webmail portals I.UA (i-ua.cc.cd) and bigmir.net (bigmir-net.cc.cd), and META.UA (meta-ua.cc.cd) — the same portals UNC1151 targeted in a 2022 campaign. A distinctive fingerprint (HTTP 404 'VPS2 endpoint only for WebSocket' on ports 3001/3002) let researchers pivot to additional related hosts.
The same actor cluster (tracked by ESET as FrostyNeighbor and separately reported by TheHackerNews/SecurityAffairs) has run a parallel, more technically involved campaign against Ukrainian government, defense, and military targets since March 2026: geofenced malicious PDFs impersonating Ukrtelecom serve a benign decoy to any non-Ukrainian IP, while Ukrainian-geolocated victims receive a RAR archive containing a JavaScript-launched PicassoLoader stage. PicassoLoader fingerprints the host (beaconing every 10 minutes) and, following manual operator review, drops a JavaScript-based Cobalt Strike Beacon loader as a third stage — with njRAT also previously observed in the group's toolkit. This is consistent with UNC1151's long operating history: active since at least March 2017, publicly exposed by Mandiant in November 2021 as the group behind the Belarus-aligned 'Ghostwriter' disinformation-and-hack-and-leak operation (assessed with high confidence to align with Belarusian government interests, without ruling out Russian contribution), and previously profiled by CERT Polska, Google TAG, and AttackIQ for repeated credential-phishing and disinformation operations against Ukraine, Poland, Lithuania, and Latvia.
MITRE ATT&CK techniques used in TL-2026-1223
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading
Exfiltration
T1041 Exfiltration Over C2 Channel
Credential Access
T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1557 Adversary-in-the-Middle
Collection
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1573 Encrypted Channel
Discovery
T1082 System Information Discovery; T1614 System Location Discovery
command-and-control
Initial Access
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1588 Obtain Capabilities; T1608 Stage Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information
Affected products and versions in UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket
- Google — Gmail / Google Account Login
Vulnerable versions: N/A - phishing targets account holders, not software - I.UA — I.UA Webmail Portal
Vulnerable versions: N/A - phishing targets account holders - bigmir.net — bigmir.net Webmail Portal
Vulnerable versions: N/A - phishing targets account holders - META.UA — META.UA Webmail Portal
Vulnerable versions: N/A - phishing targets account holders
Remediation for UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket
Immediate actions
- Block the documented phishing IPs (45.194.44.44, 45.194.44.46, 45.197.133.104, 111.88.74.246) and domains at email gateway and perimeter firewall
- Force logout and password reset for any account that interacted with the identified phishing domains
- Add the four documented TLS certificate SHA256 fingerprints to threat-intel blocklists / TLS inspection deny lists
- Alert high-risk individuals (opposition politicians, journalists, NGO staff in Belarus/Ukraine/Poland/Lithuania) to the specific 'suspicious account activity' Gmail lure
Workarounds
- Enforce phishing-resistant MFA (FIDO2/WebAuthn) org-wide for high-risk accounts as an interim mitigation while awaiting hardware key rollout
- Disable auto-rendering of PDF attachments from unsolicited senders for Ukrainian government/defense mail systems given the geofenced-PDF delivery vector
Longer-term hardening
- Migrate high-risk users from SMS/app-OTP MFA to FIDO2/WebAuthn hardware security keys, which are resistant to real-time relay/AiTM phishing
- Deploy DNS/web filtering and browser isolation for high-risk user populations
- Monitor for WebSocket connections to newly registered lookalike domains as a phishing-kit detection signal
- Deploy EDR with behavioral detection tuned to PicassoLoader/Cobalt Strike Beacon loader chains for Ukrainian government/defense networks
Weaknesses (CWE) in UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket
CWE-287, CWE-451, CWE-940, CWE-1021
Timeline of UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket
- UNC1151 activity assessed active since at least March 2017, initially conducting anti-NATO disinformation operations
- Group compromises legitimate news and media websites to plant fake stories, earning the public name 'Ghostwriter'; post-mid-2020 focus shifts to Belarus's neighbors
- Mandiant publishes assessment linking UNC1151 to Belarus with high confidence and Ghostwriter campaign to Belarusian government interests
- UNC1151 previously targets the same Ukrainian webmail portals (I.UA, bigmir.net) later reused as impersonation targets in the 2026 campaign
- FrostyNeighbor/PUSHCHA campaign against Ukrainian government, defense, and military targets begins, using geofenced Ukrtelecom-themed PDF lures leading to PicassoLoader and Cobalt Strike Beacon
- New WebSocket-relay phishing infrastructure (Datagear/AS200758, Poland) comes online, including account.check-profile.digital
- Spear-phishing email impersonating a Google account-security warning is sent to Belarusian pro-democracy politician Yury Hubarevich; Resident.NGO Threat Lab documents the case
- ESET reports fresh FrostyNeighbor/Ghostwriter activity targeting Ukrainian governmental organizations
- Security Affairs and TheHackerNews report Ghostwriter's resumed attacks on Ukrainian government targets using geofenced PDF phishing and Cobalt Strike
- Censys publishes certificate-pivoting research unmasking the WebSocket phishing infrastructure behind Bunny CDN and identifying a multi-domain, multi-IP campaign
- CyberSecurityNews, GBHackers, and CyberPress publish detailed technical writeups of the real-time WebSocket MFA-bypass mechanism and full IOC set
Sources cited for UNC1151 (Ghostwriter/FrostyNeighbor) Real-Time WebSocket
- UNC1151 (Ghostwriter) Hackers Target Belarusian Politician in Gmail Phishing Campaign
- UNC1151 Phishing Email Targeting Belarusian Politician Points to Multi-National Campaign
- Ghostwriter Hackers Use Real-Time WebSocket Relay to Bypass SMS and OTP MFA
- Ghostwriter Phishing Infrastructure Targets Gmail and Ukrainian Email Portal Users
- Case Study — UNC1151 Gmail Phishing ("Suspicious account activity") Targeting Belarusian Pro-Democracy Politician
- Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike
- Ghostwriter group resumes attacks on Ukrainian Government targets
- ESET details new Ghostwriter activity targeting Ukrainian government
- UNC1151 Assessed with High Confidence to have Links to Belarus, Ghostwriter Campaign Aligned with Belarusian Government Interests
More in phishing
- Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via Google Cloud Storage / Vercel / Google Sites Redirect Chain
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip Android APK + Certum-Signed ITD_Tax_Notice.exe Loader), Cloned e-Filing Portals and Refund Scams
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials
- Fake Claude Max Giveaway Phishing Campaign Uses Browser-in-the-Browser to Steal Google Credentials
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites)
Detection coverage for TL-2026-1223
As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1223 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.