Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ghostwriter Hackers Target Gmail with Phishing Emails

Ghostwriter Hackers Target Gmail with Phishing Emails

Posted on June 17, 2026 By CWS

In a recent development within the cybersecurity landscape, the hacking group known as Ghostwriter has intensified its focus on attacking Gmail users. This campaign involves sending deceptive emails that mimic official Google security alerts, aiming to harvest user credentials and bypass two-factor authentication (2FA).

Targeted Phishing Campaigns

The Ghostwriter group, also identified as UNC1151, has a history of targeting Polish email users, but has now shifted its attention to Gmail since March 2026. These attacks are primarily executed on weekdays with new phishing domains emerging frequently. The operation is characterized by its focus on individuals in influential roles, such as politicians, researchers, and journalists.

Analysts from CERT Polska have meticulously documented these activities. Their reports indicate that the group employs a wide-reaching strategy, often guessing email addresses to extend their reach, resulting in phishing messages occasionally arriving in unrelated inboxes.

Phishing Tactics and Techniques

Ghostwriter’s emails are crafted to resemble authentic Gmail administrator communications, often sent from specially created or compromised accounts with convincing Polish-language content. The messages typically warn of suspicious account activity, urging recipients to respond promptly to avoid account suspension or deletion.

Once a recipient clicks the link within these emails, they are directed to a fraudulent website that imitates the Gmail login interface. This site captures the user’s login credentials and, if applicable, requests their 2FA code, enabling attackers to intercept security codes from SMS or authentication apps.

Infrastructure and Preventative Measures

The infrastructure supporting these phishing efforts includes domains registered under extensions like .icu, .digital, and .top, alongside subdomains hosted on platforms such as Netlify. Ghostwriter’s strategy also involves using compromised Polish websites to host fake login panels, avoiding detection by maintaining the original site appearance.

CERT.PL advises users to remain cautious of emails threatening account suspension or deletion. Such messages should be treated as suspicious, and users are encouraged to verify the authenticity of the communication by visiting the service’s website directly through their browser.

In conclusion, the Ghostwriter campaign highlights the persistent threat posed by sophisticated phishing strategies. Users are urged to stay vigilant and adopt robust security practices to safeguard their personal and professional data against these evolving cyber threats.

Cyber Security News Tags:2FA, Belarusian hackers, CERT Polska, credential theft, Cybersecurity, email threats, fake login pages, Ghostwriter, Gmail security, Hacking, intelligence gathering, Phishing, Polish email services, UNC1151

Post navigation

Previous Post: Cyberattack Uses Fake CAPTCHA to Deploy Malware
Next Post: Cybercriminals Exploit Screen-Sharing to Steal Legal Data

Related Posts

Threat Actors Using CrossC2 Tool to Expand Cobalt Strike to Operate on Linux and macOS Threat Actors Using CrossC2 Tool to Expand Cobalt Strike to Operate on Linux and macOS Cyber Security News
Top 10 High-Risk Vulnerabilities Of 2025 that Exploited in the Wild Top 10 High-Risk Vulnerabilities Of 2025 that Exploited in the Wild Cyber Security News
Cloudflare Discloses Technical Details Behind Massive Outage that Breaks the Internet Cloudflare Discloses Technical Details Behind Massive Outage that Breaks the Internet Cyber Security News
Critical Telegram Desktop Bug Exposed Chat Data Critical Telegram Desktop Bug Exposed Chat Data Cyber Security News
Phishing Scams Exploit AI Tool Brands for Credential Theft Phishing Scams Exploit AI Tool Brands for Credential Theft Cyber Security News
Hackers Exploit Google Services for Phishing Scams Hackers Exploit Google Services for Phishing Scams Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Homebrew 7.0.0 Unveils Vulnerability Scanner and Enhanced Security
  • Major Breach at Japan’s Digital Agency Exposes 240,000 Records
  • Critical Cisco Email Gateway Flaw Exploited, CISA Warns
  • Underground AI Service ‘Luciferus’ Promoted by Hackers
  • Microsoft’s AI Code of Conduct Prohibits Cyberattacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Homebrew 7.0.0 Unveils Vulnerability Scanner and Enhanced Security
  • Major Breach at Japan’s Digital Agency Exposes 240,000 Records
  • Critical Cisco Email Gateway Flaw Exploited, CISA Warns
  • Underground AI Service ‘Luciferus’ Promoted by Hackers
  • Microsoft’s AI Code of Conduct Prohibits Cyberattacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark