Belling the BEAR
ID: 7ba6e704-06d2-4774-9a60-9281ab012936
STIX ID: report--7ba6e704-06d2-4774-9a60-9281ab012936
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2016-10-19
Last Modified Date: 2016-10-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ThreatConnect documents sustained targeting of Bellingcat by Russian-linked actors: a FANCY BEAR (APT28) spearphishing and credential-harvesting campaign (multiple Gmail‑spoofing messages, Bitly/TinyURL redirects, target-specific base64 strings) and a CyberBerkut defacement/leak that exposed a contributor's personal data; the report provides timelines, attributed infrastructure (domains, name servers, IPs, sender emails), screenshots of phishing lures, and an assessment of possible coordination between the groups while advising defensive measures such as ubiquitous two‑factor authentication.
