logo

BlueDelta’s Persistent Campaign Against UKR.NET

ID: 7df3d600-a511-5980-b0f9-9759e5416b3f

STIX ID: report--7df3d600-a511-5980-b0f9-9759e5416b3f

Feed Name: Recorded Future Blog

Threat Score
85/100

Date Published: 2025-12-17

Date Updated: 2026-04-28

...
...

Recorded Future’s Insikt Group observed a sustained BlueDelta (GRU-linked) credential-harvesting campaign targeting UKR.NET users between June 2024 and April 2025. The actors distributed phishing PDFs linking to Mocky-hosted fake login pages that exfiltrated usernames, passwords, and 2FA codes, and abused free tunneling/hosting services (ngrok, Serveo, DNS EXIT, Byet, Blogger) and link shorteners to evade detection; the report documents infrastructure, IOCs, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.