logo

Belling the BEAR

ID: 7ba6e704-06d2-4774-9a60-9281ab012936

STIX ID: report--7ba6e704-06d2-4774-9a60-9281ab012936

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2016-10-19

Last Modified Date: 2016-10-19

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ThreatConnect documents sustained targeting of Bellingcat by Russian-linked actors: a FANCY BEAR (APT28) spearphishing and credential-harvesting campaign (multiple Gmail‑spoofing messages, Bitly/TinyURL redirects, target-specific base64 strings) and a CyberBerkut defacement/leak that exposed a contributor's personal data; the report provides timelines, attributed infrastructure (domains, name servers, IPs, sender emails), screenshots of phishing lures, and an assessment of possible coordination between the groups while advising defensive measures such as ubiquitous two‑factor authentication.