GRU's BlueDelta Targets Key Networks in Europe with Multi-Phase Espionage Campaigns
ID: eedff9df-3bac-4ab5-bed7-863a9569979d
STIX ID: report--eedff9df-3bac-4ab5-bed7-863a9569979d
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2024-05-29
Last Modified Date: 2024-05-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group documents BlueDelta (attributed to the GRU) conducting a multi-phase espionage campaign across Europe that deployed the Headlace infostealer, extensive credential harvesting pages, and living-off-the-land tactics. The actor abused free hosting and API services (GitHub, Mocky, InfinityFree, Pipedream, Webhook.site) and compromised Ubiquiti EdgeRouters to relay 2FA/CAPTCHA and exfiltrate credentials, targeting Ukrainian defense entities, weapons import/export firms, European infrastructure, and Azerbaijani think tanks; the report includes technical infection-chain details, IoCs, and mitigations.
