logo

GRU-Linked BlueDelta Evolves Credential Harvesting

ID: 60512e46-4be0-4495-b2b2-cb74b96657fe

STIX ID: report--60512e46-4be0-4495-b2b2-cb74b96657fe

Threat Score

85/100

Uploaded: 2026-08-11

Published Date: 2026-01-06

Last Modified Date: 2026-01-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group reports that BlueDelta, a Russian GRU-linked APT, ran targeted credential-harvesting campaigns between February and September 2025 against energy, nuclear, government, and research-linked targets in Türkiye, Europe, North Macedonia, and Uzbekistan. The group used localized lures and legitimate PDF documents, impersonated OWA/Google/Sophos login portals, and abused free hosting and tunneling services (Webhook.site, InfinityFree, Byet, ngrok, ShortURL) to capture credentials, send page-open beacons, and redirect victims to legitimate sites; the report includes technical code snippets, infrastructure IoCs, mitigation guidance, and ATT&CK mappings.