FancyBear Server Exposure Reveals Stolen Credentials, 2FA Secrets and NATO-Linked Targets
ID: 91509f82-0c17-59fc-b3c6-02b3eff3c879
STIX ID: report--91509f82-0c17-59fc-b3c6-02b3eff3c879
Feed Name: cybersecurityNews.com
A security researcher exposure revealed FancyBear (APT28) running Operation Roundish from an open NameCheap VPS (203.161.50.145) that leaked ~2,800 government/military emails, 240 credential sets (including 256 real TOTP secrets), 11,500 contacts and full C2/source code; the group used a Roundcube XSS and a JavaScript module (keyTwoAuth.js) to silently extract TOTP secrets and recovery codes to zhblz.com, enabling invisible 2FA bypass—victims span multiple European governments and NATO-linked addresses; immediate actions include rotating TOTP secrets, auditing Sieve forwarding rules (notably entries named "SystemProtect"/"SystemHealthChek"), blocking 203.161.50.145 and zhblz.com, and applying the Roundcube CVE-2023-43770 patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
