logo

Russian BlueDelta (Fancy Bear) Uses PDFs to Steal Logins in Just 2 Seconds

ID: b6ebd266-45e6-516f-890a-55f5f96dfcb5

STIX ID: report--b6ebd266-45e6-516f-890a-55f5f96dfcb5

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-01-12

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Recorded Future’s Insikt Group reports that Russian state-sponsored APT 'BlueDelta' (aka Fancy Bear) ran credential-harvesting campaigns from Feb–Sep 2025 targeting energy and nuclear research personnel in Türkiye and Europe. The group used legitimate-looking PDF lures which, after a short delay, redirect victims to fake Google/Outlook/Sophos login pages that capture credentials and exfiltrate them via free services (webhook.site, ngrok, InfinityFree), enabling low-cost but effective data theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.