By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations
Computing

Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations

News Room
Last updated: 2026/01/09 at 2:02 PM
News Room Published 9 January 2026
Share
Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations
SHARE

Jan 09, 2026Ravie LakshmananEmail Security / Threat Intelligence

Russian state-sponsored threat actors have been linked to a fresh set of credential harvesting attacks targeting individuals associated with a Turkish energy and nuclear research agency, as well as staff affiliated with a European think tank and organizations in North Macedonia and Uzbekistan.

The activity has been attributed to APT28 (aka BlueDelta), which was attributed to a “sustained” credential-harvesting campaign targeting users of UKR[.]net last month. APT28 is associated with the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU).

“The use of Turkish-language and regionally targeted lure material suggests that BlueDelta tailored its content to increase credibility among specific professional and geographic audiences,” Recorded Future’s Insikt Group said. “These selections reflect a continued interest in organizations connected to energy research, defense cooperation, and government communication networks relevant to Russian intelligence priorities.”

Cybersecurity

The cybersecurity company described the attacks as targeting a small but distinct set of victims in February and September 2025, with the campaign leveraging fake login pages that were styled to resemble popular services like Microsoft Outlook Web Access (OWA), Google, and Sophos VPN portals.

The efforts are noteworthy for the fact that unsuspecting users are redirected to the legitimate sites after the credentials are entered on the bogus landing pages, thereby avoiding raising any red flags. The campaigns have also been found to lean heavily on services like Webhook[.]site, InfinityFree, Byet Internet Services, and ngrok to host the phishing pages, exfiltrate stolen data, and enable redirections.

In a further attempt to lend them a veneer of legitimacy, the threat actors are said to have used legitimate PDF lure documents, including a publication from the Gulf Research Center related to the June 2025 Iran-Israel war and a July 2025 policy briefing calling for a new pact for the Mediterranean released by climate change think tank ECCO.

The attack chain starts with a phishing email containing a shortened link that, when clicked, redirects victims to another link hosted on webhook[.]site, which briefly displays the decoy document for about two seconds before redirecting to a second webhook[.]site that hosts a spoofed Microsoft OWA login page.

Present within this page is a hidden HTML form element that stores the webhook[.]site URL and uses JavaScript to send a

“page opened” beacon, transmit the submitted credentials to the webhook endpoint, and ultimately redirect back to the PDF hosted on the actual website.

APT28 has also been observed conducting three other campaigns –

Cybersecurity
  • A June 2025 campaign that deployed a credential-harvesting page mimicking a Sophos VPN password reset page hosted on infrastructure provided by InfinityFree to harvest credentials entered into the form and redirect victims to a legitimate Sophos VPN portal belonging to an unnamed E.U. think tank
  • A September 2025 campaign that used credential-harvesting pages hosted on InfinityFree domains to falsely warn users of expired passwords to trick them into entering their credentials and redirect to a legitimate login page associated with a military organization in the Republic of North Macedonia and an IT integrator based in Uzbekistan
  • An April 2025 campaign that used a fake Google password reset page hosted on Byet Internet Services to gather victims’ credentials and exfiltrate them to an ngrok URL

“BlueDelta’s consistent abuse of legitimate internet service infrastructure demonstrates the group’s continued reliance on disposable services to host and relay credential data,” the Mastercard-owned company said. “These campaigns underscore the GRU’s sustained commitment to credential harvesting as a low-cost, high-yield method of collecting information that supports Russian intelligence objectives.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Danske Bank appoints its first head of AI – UKTN Danske Bank appoints its first head of AI – UKTN
Next Article Amazon Brings Alexa+ to the Web as AI Competition Heats Up Amazon Brings Alexa+ to the Web as AI Competition Heats Up
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Vivo X200 to offer long range offline connectivity & Dimensity 9400 · TechNode
Vivo X200 to offer long range offline connectivity & Dimensity 9400 · TechNode
Computing
Best monitor deal: Get the Samsung Odyssey G8 QD-OLED gaming monitor for its lowest price yet
Best monitor deal: Get the Samsung Odyssey G8 QD-OLED gaming monitor for its lowest price yet
News
I just watched the ‘Industry’ season 4 premiere and it’s the same delightfully unhinged show I fell in love with
I just watched the ‘Industry’ season 4 premiere and it’s the same delightfully unhinged show I fell in love with
News
WeChat begins beta testing for HarmonyOS NEXT · TechNode
WeChat begins beta testing for HarmonyOS NEXT · TechNode
Computing

You Might also Like

Vivo X200 to offer long range offline connectivity & Dimensity 9400 · TechNode
Computing

Vivo X200 to offer long range offline connectivity & Dimensity 9400 · TechNode

3 Min Read
WeChat begins beta testing for HarmonyOS NEXT · TechNode
Computing

WeChat begins beta testing for HarmonyOS NEXT · TechNode

1 Min Read
Ubisoft issues ambiguous response to Tencent buyout speculations · TechNode
Computing

Ubisoft issues ambiguous response to Tencent buyout speculations · TechNode

1 Min Read
Dead or Alive app designed for people living alone sparks debate in China · TechNode
Computing

Dead or Alive app designed for people living alone sparks debate in China · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?