Threat Group-4127 Targets Google Accounts
ID: 65351d2b-920a-4c82-a790-d42745c71042
STIX ID: report--65351d2b-920a-4c82-a790-d42745c71042
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2017-02-22
Last Modified Date: 2017-02-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
SecureWorks CTU documents a 2015 TG-4127 (APT28/Fancy Bear) spearphishing campaign that used spoofed Google Account login pages and Bitly-shortened links to harvest credentials from approximately 1,881 Google Accounts (4,396 phishing URLs). Targets included government and military personnel, journalists, NGOs, and supply-chain actors—primarily focused on Russia and former Soviet states but also affecting Western organizations—while CTU assessed with moderate confidence the group is operating from the Russian Federation; the report highlights the campaign’s methods, target analysis, measured click rates, and recommendations to educate users about shortened links and phishing risks.
