Hackers Linked to Belarus Target Google Account of Yury Hubarevich

Main
Юрий Губаревич. Фото: ОПК

Belarusian politician Yury Hubarevich, coordinator of the “Personnel Reserve” initiative, head of the “Za Svabodu” movement, and a member of the Belarusian Coordination Council, became the target of a phishing attack. The incident was investigated by Resident.ngo, an organization focused on digital security for NGOs, media outlets, and activists in Belarus, Ukraine, Moldova, and other Eastern European countries.

According to the researchers, Google Threat Intelligence linked the attack infrastructure to UNC1151, a cyber-espionage group associated with Belarus and connected to Ghostwriter operations.

The incident occurred on May 29. Hubarevich received an email in Russian disguised as a Google notification about suspicious activity on his account. The message claimed that the account would be deleted within 24 hours unless the user completed a verification process. The politician forwarded the email to cybersecurity specialists.

Hubarevich told Reform.news that he receives phishing emails regularly and that, in most cases, they are not difficult to identify. In addition, email filters usually do a good job of screening out such messages by sending them to the spam folder. However, what attracted his attention this time was that the email landed in his inbox. In his view, this may indicate a more targeted attack and suggest that the attackers adapted their settings to a specific mailbox.

“I decided to provide the email source data to specialists for analysis and to help develop additional recommendations for other users,” he said.

At the same time, Hubarevich stressed that the email account was not compromised and that the attackers failed to achieve their objectives.

He also urged users to remain calm in similar situations and avoid clicking on suspicious links, even if messages contain threats about an “account suspension” or other forms of pressure.

“Such attacks are designed specifically to provoke hasty and poorly considered actions,” he added.

Resident.ngo’s analysis showed that the link in the email first led to a compromised third-party website and then redirected the victim to a fake Google login page. The phishing site relayed the credentials entered by the user to the attackers in real time, including passwords and one-time two-factor authentication codes. This method allows attackers to gain immediate access to a victim’s genuine account.

The report notes that the email was sent from a legitimate Gmail account and successfully passed standard email authentication checks. The sender’s name visually resembled “Account Support” but contained Cyrillic characters that looked similar to Latin letters.

Experts emphasize that such attacks can bypass protections based on SMS codes and authenticator applications because the codes are intercepted in real time. Specialists identify FIDO2 hardware security keys and passkey technology as the most effective protection against these schemes.

🔥 Support Reform.news with a donation!
REFORM.news (formerly REFORM.by)
Add a comment

Attention, pre-moderation. If you are in Belarus, do not leave a comment without VPN enabled.