Belarusian Hackers Target Yury Hubarevich with Sophisticated Phishing Attack

Belarusian Hackers Target Yury Hubarevich with Sophisticated Phishing Attack

First seen 5 Jun 2026, 14:10 UTC Reform.Newsresident.ngoCert.PlNashanivacert.pl+3 88% similarity 77.0

Article Content

Browse articles
ThreatCluster

On May 29, 2026, Yury Hubarevich, a prominent Belarusian politician, was targeted in a phishing attack linked to the Belarusian espionage group UNC1151. The attack involved an email disguised as a Google notification, claiming suspicious activity on his account and threatening deletion unless verified. Hubarevich recognized the phishing attempt and reported it to cybersecurity experts at RESIDENT.NGO. The phishing method utilized a compromised third-party website that redirected victims to a fake Google login page, capturing usernames, passwords, and real-time 2FA codes. Google Threat Intelligence confirmed the phishing domain's association with UNC1151, known for targeting opposition figures in Belarus and surrounding regions. The email passed standard authentication checks, making it a sophisticated attack. Hubarevich's account was not compromised due to his awareness of the threat. Experts recommend using FIDO2 security keys or passkeys to mitigate such phishing risks.

Key Points: • Yury Hubarevich was targeted in a sophisticated phishing attack linked to UNC1151. • The phishing email claimed account deletion unless verification was completed, exploiting urgency. • Real-time interception of 2FA codes makes traditional SMS and authenticator methods insufficient.

ThreatCluster AI

Timeline

2026-05-29
Yury Hubarevich targeted in phishing attack
Hubarevich received a phishing email disguised as a Google notification about suspicious account activity.
resident.ngo
2026-05-29
Phishing email reported to cybersecurity experts
Hubarevich forwarded the suspicious email to RESIDENT.NGO, prompting an investigation.
Reform.News
2026-06-04
Incident analysis published by RESIDENT.NGO
The analysis confirmed the phishing method and linked the attack to UNC1151, detailing the real-time interception technique.
resident.ngo

Community

Browse all →