FancyBear Server Leak Exposes Stolen Credentials, 2FA Secrets, NATO Targets
ID: 6c7135f8-646f-5b36-86c3-c103d34c6729
STIX ID: report--6c7135f8-646f-5b36-86c3-c103d34c6729
Feed Name: GBHackers
Researchers discovered an exposed APT28/FancyBear C2 server (203.161.50.145) containing source code, payloads, logs and exfiltrated data: ~2,800 emails, 240+ credential sets including TOTP 2FA secrets, forwarding rules, and 11,500+ contacts. The toolkit abuses Roundcube/SquirrelMail XSS payloads to steal credentials, harvest mailboxes, create persistent forwarding rules, and extract TOTP seeds, enabling long-term access to government and military mailboxes across several NATO‑aligned states; Censys and Hunt.io telemetry show the actor operated from the same server over an extended period despite exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
