logo

Threat Group-4127 Targets Google Accounts

ID: 65351d2b-920a-4c82-a790-d42745c71042

STIX ID: report--65351d2b-920a-4c82-a790-d42745c71042

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2017-02-22

Last Modified Date: 2017-02-22

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
SecureWorks CTU documents a 2015 TG-4127 (APT28/Fancy Bear) spearphishing campaign that used spoofed Google Account login pages and Bitly-shortened links to harvest credentials from approximately 1,881 Google Accounts (4,396 phishing URLs). Targets included government and military personnel, journalists, NGOs, and supply-chain actors—primarily focused on Russia and former Soviet states but also affecting Western organizations—while CTU assessed with moderate confidence the group is operating from the Russian Federation; the report highlights the campaign’s methods, target analysis, measured click rates, and recommendations to educate users about shortened links and phishing risks.