Fancy Bear’s Phishing Fiesta: GRU’s Latest Cyber Shenanigans Target Ukrainian Emails

APT28, also known as BlueDelta, is on a phishing frenzy, targeting UKR.net users with fake login pages. Their goal? Harvest credentials while impersonating legitimate services. From tinyurl trickery to PDF phishiness, it’s all part of a broader espionage agenda. Seems like Fancy Bear is all about that bear-illiant data collection!

Pro Dashboard

Hot Take:

Looks like Fancy Bear is back at it again, proving that the only thing they fancy more than cyber espionage is collecting email credentials like they’re rare Pokémon cards. Someone get these bears a hobby that doesn’t involve phishing!

Key Points:

  • APT28, aka Fancy Bear, is targeting Ukrainian users via a credential-harvesting campaign.
  • The campaign includes fake UKR[.]net login pages and phishing emails.
  • Links to these fake pages are masked using URL shortening services and subdomain redirection.
  • APT28 has shifted from using compromised routers to proxy tunneling services.
  • This operation supports Russia’s intelligence objectives amid the ongoing conflict in Ukraine.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?