A phishing operation attributed to Ghostwriter, also tracked as UNC1151, shows how attackers can turn a normal sign-in flow into a credential-grab that reaches beyond the password field.
A reported UNC1151 Ghostwriter campaign puts a familiar weak point back under the microscope: code-based 2FA can still be trapped by a convincing fake login flow.
A reported Ghostwriter campaign now focuses on personal inboxes tied to senior Polish public figures and their relatives, turning private email into a high-value attack surface.