What happened
Google's Threat Analysis Group reported in May 2022 that the Belarus-attributed actor Ghostwriter had resumed credential phishing against Gmail accounts belonging to Ukrainian government and military personnel amid the Russian invasion. Google said no accounts were compromised in that campaign. The same reporting covered Russian GRU-attributed APT28 distributing a credential-stealing payload to Ukrainian users and FSB-attributed Turla targeting Baltic defence organisations.
How the deception worked
Ghostwriter sent messages containing links to legitimate but compromised third-party websites that hosted the first-stage phishing page, which lends the URL an innocuous reputation and defeats simple domain blocklists. Users who clicked were redirected to attacker-controlled infrastructure presenting a replica webmail sign-in page, where entered credentials were captured. The campaign leaned on wartime urgency and the volume of official correspondence flowing to government and military staff, conditions in which recipients process messages quickly and are primed to expect unfamiliar senders and new systems.
AI involvement · No AI reported
No AI involvement reported.
The control that would have caught it· our reading, not a claim from the sources
Enrolling government and military accounts in advanced protection with hardware security keys, and treating links to unfamiliar third-party sites as untrusted regardless of domain reputation, blocks this class of harvesting.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.