BlueDelta Hackers Target Microsoft OWA, Google, and Sophos VPN to Steal Credentials
ID: ef1c3a2c-0e06-542f-82a6-812b3844aea4
STIX ID: report--ef1c3a2c-0e06-542f-82a6-812b3844aea4
Feed Name: GBHackers
Recorded Future’s Insikt Group describes a sophisticated BlueDelta (GRU-linked APT28) credential-harvesting campaign from February–September 2025 that targeted Turkish energy and nuclear research, a European think tank, and organizations in North Macedonia and Uzbekistan. The actors used legitimate PDF publications as lures, multi-stage redirection chains and free hosting/tunneling services (Webhook.site, InfinityFree, Byet, ngrok, ShortURL) to display documents, capture beacons and exfiltrate credentials via JSON POSTs; the report includes specific infrastructure indicators and recommends phishing-resistant MFA, deny-listing unnecessary free hosting services, and monitoring for proxy-based authentication attempts. Recorded Future assesses BlueDelta will continue evolving these operations into 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
