Russian BlueDelta (Fancy Bear) Uses PDFs to Steal Logins in Just 2 Seconds
ID: b6ebd266-45e6-516f-890a-55f5f96dfcb5
STIX ID: report--b6ebd266-45e6-516f-890a-55f5f96dfcb5
Feed Name: HackRead
Recorded Future’s Insikt Group reports that Russian state-sponsored APT 'BlueDelta' (aka Fancy Bear) ran credential-harvesting campaigns from Feb–Sep 2025 targeting energy and nuclear research personnel in Türkiye and Europe. The group used legitimate-looking PDF lures which, after a short delay, redirect victims to fake Google/Outlook/Sophos login pages that capture credentials and exfiltrate them via free services (webhook.site, ngrok, InfinityFree), enabling low-cost but effective data theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
