logo

FancyBear Server Leak Exposes Stolen Credentials, 2FA Secrets, NATO Targets

ID: 6c7135f8-646f-5b36-86c3-c103d34c6729

STIX ID: report--6c7135f8-646f-5b36-86c3-c103d34c6729

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Researchers discovered an exposed APT28/FancyBear C2 server (203.161.50.145) containing source code, payloads, logs and exfiltrated data: ~2,800 emails, 240+ credential sets including TOTP 2FA secrets, forwarding rules, and 11,500+ contacts. The toolkit abuses Roundcube/SquirrelMail XSS payloads to steal credentials, harvest mailboxes, create persistent forwarding rules, and extract TOTP seeds, enabling long-term access to government and military mailboxes across several NATO‑aligned states; Censys and Hunt.io telemetry show the actor operated from the same server over an extended period despite exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.