logo

BlueDelta Espionage: Russian Hackers Abuse Free Apps to Target Energy Sector

ID: ab592c6d-3ecb-5602-b9f2-600ccc4828e3

STIX ID: report--ab592c6d-3ecb-5602-b9f2-600ccc4828e3

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-01-09

Date Updated: 2026-04-22

Author: Ddos

...
...

BlueDelta, a GRU-linked APT, ran a focused credential-harvesting campaign (observed Feb–Sep 2025) against energy, nuclear research, think-tank, and government targets across Europe and the Middle East, abusing legitimate free services (Webhook.site, InfinityFree, ngrok) to host fake OWA/Google/Sophos VPN login pages, using genuine PDF lures and custom JavaScript to capture credentials and redirect victims to real portals to avoid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.