logo

FancyBear Server Exposure Reveals Stolen Credentials, 2FA Secrets and NATO-Linked Targets

ID: 91509f82-0c17-59fc-b3c6-02b3eff3c879

STIX ID: report--91509f82-0c17-59fc-b3c6-02b3eff3c879

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-18

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A security researcher exposure revealed FancyBear (APT28) running Operation Roundish from an open NameCheap VPS (203.161.50.145) that leaked ~2,800 government/military emails, 240 credential sets (including 256 real TOTP secrets), 11,500 contacts and full C2/source code; the group used a Roundcube XSS and a JavaScript module (keyTwoAuth.js) to silently extract TOTP secrets and recovery codes to zhblz.com, enabling invisible 2FA bypass—victims span multiple European governments and NATO-linked addresses; immediate actions include rotating TOTP secrets, auditing Sieve forwarding rules (notably entries named "SystemProtect"/"SystemHealthChek"), blocking 203.161.50.145 and zhblz.com, and applying the Roundcube CVE-2023-43770 patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.