logo

FancyBear Exposed: Major OPSEC Blunder Inside Russian Espionage Ops

ID: cba54b8e-4485-5d9f-be39-c83c918f8260

STIX ID: report--cba54b8e-4485-5d9f-be39-c83c918f8260

Feed Name: Ctrl-Alt-Int3l

Threat Score
92/100

Date Published: 2026-03-16

Date Updated: 2026-04-19

Author: Ctrl-Alt-Intel

...
...

Ctrl-Alt-Intel analysed an exposed open-directory tied to FancyBear (APT28/STRONTIUM) and recovered a near-complete espionage toolkit and telemetry showing XSS-based compromises of Roundcube and SquirrelMail, exfiltration of 11,000+ emails, 11,500+ harvested contacts, 240+ credential/TOTP captures, and 140+ Sieve forwarding rules that persisted access across government and military targets in Ukraine, Romania, Greece, Serbia and Bulgaria; core C2 infrastructure was hosted at zhblz.com / 203.161.50.145 and operated for 500+ days.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.