Russia’s Fancy Bear APT Doubles Down on Global Secrets Theft
ID: fb9c1f81-cdc6-52f3-b15f-74f79b9ea267
STIX ID: report--fb9c1f81-cdc6-52f3-b15f-74f79b9ea267
Feed Name: Dark Reading
Threat Score
Recorded Future attributes a Feb–Sep 2025 credential-harvesting campaign to a GRU-linked APT (BlueDelta/Fancy Bear) that targeted strategic organizations across the Balkans, Middle East, and Central Asia using spearphishing with legitimate PDF lures and cloned login pages for Sophos VPN, Google, and Microsoft Outlook; attackers used commercial and free hosting to reduce technical fingerprints and harvest credentials for intelligence collection and follow-on access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
