logo

Credential-harvesting attacks by APT28 hit Turkish, European, and Central Asian organizations

ID: 3164178a-5286-598e-8f22-0cb81cd0d19c

STIX ID: report--3164178a-5286-598e-8f22-0cb81cd0d19c

Feed Name: Security Affairs

Threat Score
82/100

Date Published: 2026-01-12

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

**Executive Summary:** Recorded Future’s Insikt Group attributes a 2025 credential‑harvesting campaign to Russia‑linked APT28 (BlueDelta) that targeted Turkish energy and nuclear staff, European think‑tank personnel, and organizations in North Macedonia and Uzbekistan using regionally tailored PDF lures and spoofed Outlook/Google/Sophos VPN login pages hosted on free services (Webhook.site, InfinityFree, Byet) and ngrok proxies; the report provides IoCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.