APT28__2016__Russia_Hacks_Bellingcat_MH17_Investigation_ThreatConnect.pdf
ID: 616b8bb8-4170-40cf-9cfc-4f6f5f016419
STIX ID: report--616b8bb8-4170-40cf-9cfc-4f6f5f016419
Threat Score
82/100
Uploaded: 2026-08-07
Published Date: 2016-12-21
Last Modified Date: 2016-12-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ThreatConnect analyzes targeted operations against Bellingcat between 2015–2016, attributing a prolonged spearphishing and credential-harvesting campaign to FANCY BEAR (with related disruptive defacements and leaks by CyberBerkut). The report documents phishing templates spoofing Google, use of URL shorteners to obfuscate malicious landing pages, SMS/2FA interception or account-server access, and enumerates domain, mailserver, and IP indicators used in the attacks, concluding the activity is consistent with state-backed Russian actors aiming to compromise journalists and their contacts.
