logo

UK ties GRU to stealthy Microsoft 365 credential-stealing malware

ID: 83d3db3c-8555-509e-bec5-33f0afe31721

STIX ID: report--83d3db3c-8555-509e-bec5-33f0afe31721

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-07-18

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The UK NCSC attributes a sophisticated credential‑stealing malware family dubbed “Authentic Antics” to APT28 (Fancy Bear); the malware runs inside Outlook to harvest Microsoft 365 credentials and OAuth tokens, exfiltrates data by sending messages from the victim’s own mailbox while disabling “save to sent,” and comprises a dropper, infostealer and PowerShell scripts enabling stealthy, long‑lived access—an attribution that prompted UK sanctions against GRU units and individuals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.