logo

GRU-Linked BlueDelta Evolves Credential Harvesting

ID: 1b402ebb-59d8-500a-88c3-75cc8112e523

STIX ID: report--1b402ebb-59d8-500a-88c3-75cc8112e523

Feed Name: Recorded Future Blog

Threat Score
85/100

Date Published: 2026-01-07

Date Updated: 2026-04-28

...
...

Between February and September 2025 Recorded Future’s Insikt Group tracked BlueDelta (GRU-linked) credential-harvesting campaigns that used localized lures and spoofed login portals (Microsoft OWA, Google, Sophos VPN) to capture credentials. The group abused free hosting and tunneling services (Webhook.site, InfinityFree, Byet, ngrok, ShortURL), employed legitimate PDF lures for realism, implemented JavaScript-based exfiltration and redirection to real sites to evade detection, and targeted researchers and institutions linked to energy, defense, and government communications in Türkiye and Europe; the report includes IoCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.