Threat Intelligence

APT28 targets Ukrainian users in sustained credential harvesting campaign

Binary code on flag of Russia. Program source code or Hacker concept on Russian flag. Russia digital technology security, hacking or programming

A sustained credential-harvesting campaign has been attributed to APT28, a Russian state-sponsored threat actor, targeting users of UKR[.]net, a popular Ukrainian webmail and news service. This activity builds upon previous findings detailing the group's attacks on European networks. The campaign highlights the persistent efforts of APT28, also known as BlueDelta, to gather intelligence, according to a recent report by The Hacker News.

The campaign, observed between June 2024 and April 2025, involves APT28 deploying UKR[.]net-themed login pages on legitimate services like Mocky. Phishing emails containing PDF documents with links to these pages are distributed to entice users into entering their credentials and two-factor authentication (2FA) codes. The threat actor utilizes URL shorteners and subdomains on platforms like Blogger for redirection. APT28, affiliated with Russia's GRU, has transitioned from using compromised routers to proxy tunneling services like ngrok and Serveo to relay stolen information. This shift is likely an adaptive response to infrastructure takedowns.

The ongoing campaign underscores the Russian GRU's persistent interest in compromising Ukrainian user credentials to support intelligence-gathering operations amidst the ongoing conflict. The use of anonymized tunneling infrastructure demonstrates an adaptive approach to evading detection and mitigation efforts.

Source: The Hacker News

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds