BlueDelta Espionage: Russian Hackers Abuse Free Apps to Target Energy Sector
ID: ab592c6d-3ecb-5602-b9f2-600ccc4828e3
STIX ID: report--ab592c6d-3ecb-5602-b9f2-600ccc4828e3
Feed Name: securityonline.info
Threat Score
BlueDelta, a GRU-linked APT, ran a focused credential-harvesting campaign (observed Feb–Sep 2025) against energy, nuclear research, think-tank, and government targets across Europe and the Middle East, abusing legitimate free services (Webhook.site, InfinityFree, ngrok) to host fake OWA/Google/Sophos VPN login pages, using genuine PDF lures and custom JavaScript to capture credentials and redirect victims to real portals to avoid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
