GRU-Linked BlueDelta Evolves Credential Harvesting
ID: 60512e46-4be0-4495-b2b2-cb74b96657fe
STIX ID: report--60512e46-4be0-4495-b2b2-cb74b96657fe
Threat Score
85/100
Uploaded: 2026-08-11
Published Date: 2026-01-06
Last Modified Date: 2026-01-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group reports that BlueDelta, a Russian GRU-linked APT, ran targeted credential-harvesting campaigns between February and September 2025 against energy, nuclear, government, and research-linked targets in Türkiye, Europe, North Macedonia, and Uzbekistan. The group used localized lures and legitimate PDF documents, impersonated OWA/Google/Sophos login portals, and abused free hosting and tunneling services (Webhook.site, InfinityFree, Byet, ngrok, ShortURL) to capture credentials, send page-open beacons, and redirect victims to legitimate sites; the report includes technical code snippets, infrastructure IoCs, mitigation guidance, and ATT&CK mappings.
