Recorded Future’s Insikt Group reported sustained credential-harvesting operations by Russia-linked APT28 (aka BlueDelta/Fancy Bear) targeting individuals tied to a Turkish energy and nuclear research agency, European think tanks, and organizations in North Macedonia and Uzbekistan. Activity observed from February to September 2025 used regionally tailored lures aligned with Russian intelligence priorities around energy, defense, and policy, with victims redirected to legitimate sites after credential theft to reduce suspicion.
The campaigns relied on fake login portals impersonating Microsoft Outlook/OWA, Google, and Sophos VPN to capture credentials, and used low-cost, resilient infrastructure including free hosting and tunneling services (e.g., ngrok, Webhook[.]site, InfinityFree, and Byet Internet Services) to host pages and exfiltrate data. Multiple operations incorporated legitimate PDF lure documents (e.g., think tank and foundation publications) to increase authenticity and bypass email security controls, reflecting continued emphasis on scalable credential theft rather than novel malware deployment.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-01-12, multiple outlets reported Recorded Future Insikt Group's findings that APT28 had conducted credential-harvesting campaigns from February through September 2025 against Turkish energy and nuclear agency staff, European think tanks, and organizations in North Macedonia and Uzbekistan. The report detailed the use of spoofed OWA, Google, and Sophos VPN portals, PDF lures, and disposable infrastructure including InfinityFree, Webhook.site, and ngrok.
In September 2025, APT28 used expired-password themed Outlook Web Access phishing pages that redirected victims to legitimate portals associated with a North Macedonian military organization and an IT firm in Uzbekistan. This wave highlighted the campaign's continued regional tailoring and focus on defense- and government-linked targets.
On 2025-06-04, APT28 used a spoofed Sophos VPN password-reset page as part of its credential-harvesting operations. The tactic targeted users in sensitive sectors and reflected the group's continued adaptation of familiar enterprise login themes.
In April 2025, the campaign expanded to include Portuguese-language phishing themed as Google password resets. The lures were tailored to regional targets and continued APT28's use of fake login pages to capture credentials.
Recorded Future's Insikt Group observed Russia-linked APT28 launching credential-harvesting activity in February 2025 against Turkish, European, and Central Asian organizations aligned with Russian intelligence interests. Early activity used spoofed Microsoft Outlook Web Access login pages, legitimate-looking PDF lures, and low-cost infrastructure to steal credentials and redirect victims to real sites.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.