logo

GRU's BlueDelta Targets Key Networks in Europe with Multi-Phase Espionage Campaigns

ID: eedff9df-3bac-4ab5-bed7-863a9569979d

STIX ID: report--eedff9df-3bac-4ab5-bed7-863a9569979d

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2024-05-29

Last Modified Date: 2024-05-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group documents BlueDelta (attributed to the GRU) conducting a multi-phase espionage campaign across Europe that deployed the Headlace infostealer, extensive credential harvesting pages, and living-off-the-land tactics. The actor abused free hosting and API services (GitHub, Mocky, InfinityFree, Pipedream, Webhook.site) and compromised Ubiquiti EdgeRouters to relay 2FA/CAPTCHA and exfiltrate credentials, targeting Ukrainian defense entities, weapons import/export firms, European infrastructure, and Azerbaijani think tanks; the report includes technical infection-chain details, IoCs, and mitigations.