Home APT Ghostwriter Phishing Infrastructure Targets Gmail and Ukrainian Email Portal Users

Ghostwriter Phishing Infrastructure Targets Gmail and Ukrainian Email Portal Users

0
Ghostwriter Targets Email Users

The threat actor known as UNC1151, also tracked under names like Ghostwriter and FrostyNeighbor, continues to expand its aggressive spear-phishing operations across Eastern Europe.

Historically aligned with Belarusian and Russian state interests, this group originally gained notoriety in 2020 by hacking media websites to plant political disinformation.

Recent threat intelligence reveals the group has shifted heavily into credential theft, scaling its infrastructure to target high-profile individuals.

A recent attack against Belarusian pro-democracy politician Yury Hubarevich exposed a much broader network designed to steal credentials from Gmail users and popular Ukrainian email portals.

In the attack against Hubarevich, the target received a highly convincing spear-phishing email purporting to be a Google security alert.

The original phishing email, in Russian (a language widely spoken in Belarus) (Source: censys)

The message, written in Russian, warned of suspicious account activity and prompted the victim to verify his login details.

Clicking the provided link led the user to a compromised Ukrainian website that redirected to a fake Google login page. Behind the scenes, the attackers engineered a clever technical bypass for multi-factor authentication (MFA).

They used a WebSocket connection to capture passwords and authentication codes in real time, instantly relaying them back to their own servers. This live relay enabled operators to bypass SMS or one-time password (OTP) protections.

Ghostwriter Targets Email Users

The threat actors attempted to hide the true locations of their malicious servers by routing traffic through popular content delivery networks (CDNs), such as Bunny CDN and Cloudflare.

Security researchers unmasked this infrastructure by using internet-scanning tools to identify the real IP addresses hosting the domains.

By analyzing historical certificate data, they discovered that the fake authentication domain was actively hosted on an exposed IP address located in Poland.

This critical operational security failure by the attackers stripped away their CDN protection, revealing their backend systems.

Further investigation into this exposed Polish IP address revealed multiple active web servers operating on unusual network ports.

The final step in the phishing attempt. The text reads in Russian “Account verification has been initiated successfully. You’ll receive further information within 24 hours.” (Source: censys)

An HTTP request sent to port 3002 returned a specific, highly unique error message stating that it was a “VPS2 endpoint only for WebSocket.”

This distinct signature provided researchers with a valuable pivoting point to hunt for related infrastructure. Using this exact fingerprint, investigators identified three additional IP addresses exhibiting the same server behavior.

According to Censys research, these newly discovered servers hosted a massive array of fraudulent domains disguised as legitimate security or account verification portals.

Attackers registered highly deceptive domains to trick victims into handing over their sensitive credentials.

By mapping these digital certificates, the cybersecurity community confirmed that the attack on Hubarevich was not an isolated political incident but rather a small part of a massive, ongoing credential-harvesting campaign.

Indicators of Compromise

IP addressSHA256 of certificateHostname
45.197.133[.]1042434e1a88cf2effa13fc4eb335560e3cf49790ddd4bd0df7e100de9867a19748mail[.]service-support[.]digital
45.197.133[.]1046542f8fa3e1f00a3c0e9994c34d8b49d2c3d2684cf73c23a0b1030daaaaa4786accounts-verification[.]cc[.]cd
45.197.133[.]104cb5230b57589132f63441244183f24ce727d1a2f5454d7636a3548207a585

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version