logo

BlueDelta Hackers Attacking Users of Widely Used Ukrainian Webmail and News Service

ID: 266c5b8a-1a58-5b62-9ced-51feeb0c479a

STIX ID: report--266c5b8a-1a58-5b62-9ced-51feeb0c479a

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A Russian state-sponsored group known as BlueDelta (APT28/Fancy Bear) conducted a persistent credential-harvesting campaign against UKR.NET users between June 2024 and April 2025, using PDF-delivered phishing, fake login pages hosted on free services (Mocky, DNS EXIT), and multi-tier proxy tunneling (ngrok, Serveo) to capture usernames, passwords, and 2FA codes; researchers observed over 42 distinct credential-harvesting chains and technical measures to evade detection such as disabling ngrok warnings and relaying CAPTCHA challenges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.