logo

FancyBear Exposed: Major OPSEC Blunder Inside Russian Espionage Ops

ID: a8e4867b-2236-5c4b-a9e1-7dd92e006c18

STIX ID: report--a8e4867b-2236-5c4b-a9e1-7dd92e006c18

Feed Name: Ctrl-Alt-Int3l

Threat Score
92/100

Date Published: 2026-03-16

Date Updated: 2026-04-19

Author: Ctrl-Alt-Intel

...
...

Ctrl-Alt-Intel analyzed an exposed open-directory tied to FancyBear/APT28 that revealed C2 source code, XSS payloads targeting Roundcube and SquirrelMail, modular JS for credential/TOTP/address-book theft, and server telemetry showing large-scale exfiltration and persistent access. The campaign compromised government and military email accounts across Ukraine and several Balkan/Eastern European states (including NATO-related addresses), stole credentials and TOTP secrets, exfiltrated mail and address books, and created persistent Sieve forwarding rules—demonstrating a high-impact nation-state espionage operation with extensive IOCs and detailed TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.