Russian state-sponsored threat group BlueDelta (also known as APT28, Fancy Bear, and Forest Blizzard) conducted a persistent credential-harvesting campaign against users of UKR.NET, a popular Ukrainian webmail and news service, between June 2024 and April 2025. The campaign involved the use of phishing emails containing PDF lures with embedded links to fake UKR.NET login pages, designed to steal usernames, passwords, and two-factor authentication codes. BlueDelta leveraged free web services such as Mocky, DNS EXIT, ngrok, and Serveo to host these credential-harvesting pages, and used URL shorteners and Blogger subdomains to obfuscate the phishing infrastructure and redirect victims.
The operation reflects BlueDelta's adaptive tactics in response to Western-led infrastructure takedowns, with the group continuing to abuse free hosting and anonymized tunneling platforms. While specific targets were not disclosed, the campaign is assessed as part of Russia's broader intelligence-gathering efforts against Ukrainian users, supporting GRU objectives. The tools, infrastructure, and bespoke JavaScript used in this campaign are consistent with BlueDelta's established tradecraft and have not been observed in use by other Russian threat groups.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On December 17, 2025, Recorded Future published research attributing the June 2024-April 2025 UKR.NET credential-harvesting campaign to BlueDelta/APT28 and describing its phishing lures, infrastructure, and adaptation to takedowns. The report tied the activity to Russian GRU intelligence objectives in the war against Ukraine.
In May 2025, BlueDelta was also reported exploiting cross-site scripting vulnerabilities to target webmail servers in Ukraine, Bulgaria, and Romania. This marked a related expansion beyond phishing of UKR.NET users to direct exploitation of webmail platforms.
Recorded Future observed the UKR.NET credential-harvesting campaign remain active through April 2025, with more than 42 distinct harvesting chains identified. The operation showed continued refinement of multi-tiered infrastructure and phishing techniques in support of Russian intelligence collection.
After Western law enforcement and allied disruptions affected earlier GRU proxy infrastructure, BlueDelta adapted by moving from compromised routers and botnet-backed relays to anonymized tunneling services such as ngrok and Serveo. This change helped the group continue relaying stolen credentials and bypassing defenses.
During the campaign, the group distributed at least 20 malicious PDF lures containing links to fake UKR.NET login portals. The infrastructure relied on link shorteners, redirection chains, and legitimate services such as Mocky to evade detection and capture credentials.
In June 2024, BlueDelta/APT28 began a prolonged credential-harvesting operation targeting users of the Ukrainian webmail and news service UKR.NET. The campaign used phishing emails and fake login pages to steal usernames, passwords, and two-factor authentication codes.
Similar credential-phishing activity targeting ukr.net users had been observed as early as March 2022, indicating BlueDelta/APT28 interest in the platform predates the later sustained campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcethehackernews.com
Open sourcetherecord.media
Open sourcerecordedfuture.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.