The UNC1151 Gmail phishing campaign has emerged as a cyberthreat targeting internet users in Poland, with attackers now focusing on Gmail accounts and deploying phishing pages capable of stealing both passwords and two-factor authentication (2FA) credentials. According to researchers at CERT Polska, the campaign marks a notable evolution in the tactics of the Ghostwriter-linked threat group, which has been targeting email users across Poland for years.
See also: Phishing campaign imitates Adobe Document Cloud and installs malware

Also known as Ghostwriter and Storm-0257, UNC1151 has been linked by cybersecurity researchers to Belarusian state intelligence services and has remained active against Polish targets since Russia's full-scale invasion of Ukraine.
For years, UNC1151 primarily targeted users of popular Polish email providers, including Onetpasswords, Wirtualna Polska , and Interia. Since March 2026, however, the group has turned its attention to Gmail users, launching high-volume phishing operations that are conducted almost daily during business days.
CERT Polska researchers reported that the attackers are targeting a wide range of individuals, including politicians, public officials, researchers, journalists, law enforcement personnel, government employees, and people connected to them through professional, family, or social relationships.
The group also conducts campaigns against specific professional sectors and geographic regions. In some cases, phishing emails are sent to unintended recipients because attackers try to guess email addresses based on names and relationships.
The UNC1151 Gmail phishing campaign relies on deceptive emails designed to look like official Gmail security alerts. The messages often warn recipients of suspicious account activity, unauthorized login attempts, or alleged violations of service policies. Victims are urged to act quickly to avoid account suspension or permanent deletion.
The emails are typically sent from Gmail accounts created specifically for phishing operations, although attackers occasionally use compromised accounts to increase credibility. Common subject lines include warnings about security alerts, suspicious activity, and account verification requests.
See also: GHOST STADIUM: Phishing campaign targets 2026 FIFA World Cup fans

The embedded links direct recipients to fake Gmail login pages that closely mimic the genuine Google authentication portal. Once users enter their credentials, the attackers capture both usernames and passwords.
One of the most worrying developments in the campaign is its ability to collect 2FA codes. Unlike previous phishing campaigns targeting Polish email services, the latest operation includes additional prompts that ask for verification codes after entering login credentials. If a victim’s account is protected by 2FA, the phishing page automatically displays a form requesting the authentication code.
This allows attackers to steal both SMS verification codes and codes generated through apps like Google Authenticator. The researchers noted that attackers often continue to target the same victims even after unsuccessful login attempts. Multiple phishing emails can be delivered over a period of days to increase pressure and improve the chances of credential theft.
The campaign relies on a constantly evolving phishing infrastructure. According to CERT Polska, the operators use domains specifically registered for phishing activities, often leveraging top-level domains such as .icu, .digital and .top. The group also abuses hosting platforms such as Netlify by creating deceptive subdomains that mimic account verification services. Examples of domains observed in the campaign include mailverify.digital, verify-check.digital, monitoring-google-konta.netlify.app and service-auth.netlify.app.
See also: The most common phishing scams in Gmail and Outlook

Additionally, attackers host fake login panels on compromised websites belonging to legitimate organizations. Rather than replacing the main website, the phishing content is hidden within the compromised infrastructure, allowing the attacks to remain undetected for extended periods.
