Researchers exposed a major OPSEC failure by FancyBear/APT28 that revealed an active espionage operation, tracked as Operation Roundish, targeting government and military organizations across Europe. An exposed NameCheap VPS at 203.161.50.145, previously linked to the group by CERT-UA, remained in use for more than 500 days and contained a publicly accessible directory with stolen data and operational artifacts. Hunt.io first documented the campaign from an exposed directory scan, and follow-on analysis found the same infrastructure held 2,800+ exfiltrated emails, 240+ stolen credential sets including passwords and TOTP 2FA secrets, 140+ malicious email-forwarding rules, and 11,500+ harvested contact addresses from victim mailboxes.
Further investigation uncovered a second exposed directory on the same server containing FancyBear’s C2 source code, additional JavaScript payloads, telemetry logs, and evidence of broader collection activity. The operation affected entities in Ukraine, Romania, Bulgaria, Greece, Serbia, and North Macedonia, including addresses associated with four NATO member states and NATO-linked targets. Researchers also reported a previously unreported SquirrelMail XSS payload, indicating the campaign targeted multiple webmail platforms and used mailbox compromise, silent forwarding, and credential theft to sustain long-term intelligence collection.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Researchers disclosed that FancyBear used JavaScript, including keyTwoAuth.js, to steal TOTP secrets from Roundcube sessions via the twofactorgauthenticator plugin, enabling persistent 2FA bypass. The exposed logs showed 516 entries across 108 victim addresses, including targets in Ukraine, Romania, Bulgaria, Greece, Serbia, and North Macedonia, some linked to NATO member states and infrastructure.
Ctrl-Alt-Intel and Hunt.io uncovered another open directory on the same NameCheap VPS, exposing source code, payloads, telemetry logs, exfiltrated emails, stolen credentials, forwarding rules, and harvested contacts. The exposure provided rare visibility into an active APT28 espionage operation.
Breakglass Intelligence reported that APT28 used weaponized RTF documents impersonating Ukrainian emergency correspondence to coerce Windows into sending NTLMv2 hashes to attacker-controlled infrastructure via a WebDAV UNC path. The campaign primarily targeted the Ukrainian State Hydrometeorological Center and also included parallel targeting tied to Ukraine, a German-speaking European target, and Turkey.
Ctrl-Alt-Intel said its findings expanded on Hunt.io's March 2026 reporting about Operation Roundish. Hunt.io had already identified exposed FancyBear infrastructure tied to the campaign before the follow-on analysis.
Ctrl-Alt-Intel reported that the FancyBear/APT28 server at 203.161.50.145 was used for espionage operations from at least September 2024. The infrastructure supported Operation Roundish activity against government and military webmail users in Eastern and Southeastern Europe.
The reporting states the same VPS remained in use despite prior public attribution by CERT-UA, indicating the infrastructure had already been linked to APT28 before March 2026. The exact attribution date is not specified in the references.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 27 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcectrlaltintel.com
Open sourceintel.breakglass.tech
Open sourcectrlaltintel.com
Open sourcectrlaltintel.com
Open sourcectrlaltintel.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.