A sustained credential-harvesting campaign has been attributed to APT28, a Russian state-sponsored threat actor, targeting users of UKR[.]net, a popular Ukrainian webmail and news service. This activity builds upon previous findings detailing the group's attacks on European networks. The campaign highlights the persistent efforts of APT28, also known as BlueDelta, to gather intelligence, according to a recent report by The Hacker News.The campaign, observed between June 2024 and April 2025, involves APT28 deploying UKR[.]net-themed login pages on legitimate services like Mocky. Phishing emails containing PDF documents with links to these pages are distributed to entice users into entering their credentials and two-factor authentication (2FA) codes. The threat actor utilizes URL shorteners and subdomains on platforms like Blogger for redirection. APT28, affiliated with Russia's GRU, has transitioned from using compromised routers to proxy tunneling services like ngrok and Serveo to relay stolen information. This shift is likely an adaptive response to infrastructure takedowns.The ongoing campaign underscores the Russian GRU's persistent interest in compromising Ukrainian user credentials to support intelligence-gathering operations amidst the ongoing conflict. The use of anonymized tunneling infrastructure demonstrates an adaptive approach to evading detection and mitigation efforts.Source: The Hacker News
Threat Intelligence
APT28 targets Ukrainian users in sustained credential harvesting campaign

(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



