logo

APT28__2016__Russia_Hacks_Bellingcat_MH17_Investigation_ThreatConnect.pdf

ID: 616b8bb8-4170-40cf-9cfc-4f6f5f016419

STIX ID: report--616b8bb8-4170-40cf-9cfc-4f6f5f016419

Threat Score

82/100

Uploaded: 2026-08-07

Published Date: 2016-12-21

Last Modified Date: 2016-12-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ThreatConnect analyzes targeted operations against Bellingcat between 2015–2016, attributing a prolonged spearphishing and credential-harvesting campaign to FANCY BEAR (with related disruptive defacements and leaks by CyberBerkut). The report documents phishing templates spoofing Google, use of URL shorteners to obfuscate malicious landing pages, SMS/2FA interception or account-server access, and enumerates domain, mailserver, and IP indicators used in the attacks, concluding the activity is consistent with state-backed Russian actors aiming to compromise journalists and their contacts.