logo

Russia’s Fancy Bear APT Doubles Down on Global Secrets Theft

ID: fb9c1f81-cdc6-52f3-b15f-74f79b9ea267

STIX ID: report--fb9c1f81-cdc6-52f3-b15f-74f79b9ea267

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-01-09

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Recorded Future attributes a Feb–Sep 2025 credential-harvesting campaign to a GRU-linked APT (BlueDelta/Fancy Bear) that targeted strategic organizations across the Balkans, Middle East, and Central Asia using spearphishing with legitimate PDF lures and cloned login pages for Sophos VPN, Google, and Microsoft Outlook; attackers used commercial and free hosting to reduce technical fingerprints and harvest credentials for intelligence collection and follow-on access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.