BlueDelta Hackers Attacking Users of Widely Used Ukrainian Webmail and News Service
ID: 266c5b8a-1a58-5b62-9ced-51feeb0c479a
STIX ID: report--266c5b8a-1a58-5b62-9ced-51feeb0c479a
Feed Name: cybersecurityNews.com
A Russian state-sponsored group known as BlueDelta (APT28/Fancy Bear) conducted a persistent credential-harvesting campaign against UKR.NET users between June 2024 and April 2025, using PDF-delivered phishing, fake login pages hosted on free services (Mocky, DNS EXIT), and multi-tier proxy tunneling (ngrok, Serveo) to capture usernames, passwords, and 2FA codes; researchers observed over 42 distinct credential-harvesting chains and technical measures to evade detection such as disabling ngrok warnings and relaying CAPTCHA challenges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
