{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-ghostwriter-credential-phishing-against-ukrainian-government-and-militar"},"incident":{"title":"Ghostwriter credential phishing against Ukrainian government and military accounts","date":"2022-05","date_precision":"month","victim_org":"Ukrainian government and military personnel","sector":"Government","country":"Ukraine","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","Watering Hole / Malvertising"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Credential Theft","Espionage","Attempt Blocked"],"loss_usd":null,"loss_note":"No monetary loss; Google reported no accounts were compromised in the Ghostwriter campaign it described.","records_affected":null,"threat_actor":"Ghostwriter / UNC1151 (Belarus-attributed), alongside APT28 and Turla activity","summary":"Google's Threat Analysis Group reported in May 2022 that the Belarus-attributed actor Ghostwriter had resumed credential phishing against Gmail accounts belonging to Ukrainian government and military personnel amid the Russian invasion. Google said no accounts were compromised in that campaign. The same reporting covered Russian GRU-attributed APT28 distributing a credential-stealing payload to Ukrainian users and FSB-attributed Turla targeting Baltic defence organisations.","how_it_worked":"Ghostwriter sent messages containing links to legitimate but compromised third-party websites that hosted the first-stage phishing page, which lends the URL an innocuous reputation and defeats simple domain blocklists. Users who clicked were redirected to attacker-controlled infrastructure presenting a replica webmail sign-in page, where entered credentials were captured. The campaign leaned on wartime urgency and the volume of official correspondence flowing to government and military staff, conditions in which recipients process messages quickly and are primed to expect unfamiliar senders and new systems.","lessons":"Enrolling government and military accounts in advanced protection with hardware security keys, and treating links to unfamiliar third-party sites as untrusted regardless of domain reputation, blocks this class of harvesting.","confidence":"Confirmed","sources":[{"title":"Update on cyber activity in Eastern Europe","url":"https://blog.google/threat-analysis-group/update-on-cyber-activity-in-eastern-europe/","publisher":"Google Threat Analysis Group"}],"entry_type":"incident","slug":"2022-ghostwriter-credential-phishing-against-ukrainian-government-and-militar","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-ghostwriter-credential-phishing-against-ukrainian-government-and-militar"}}