Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

BlueDelta Hackers Attacking Users of Widely Used Ukrainian Webmail and News Service

A recent credential-harvesting operation has been identified targeting users of UKR.NET, a widely-utilized Ukrainian webmail and news service.

A recent credential-harvesting operation has been identified targeting users of UKR.NET, a widely-utilized Ukrainian webmail and news service.

The campaign is attributed to BlueDelta, recognized as a Russian state-sponsored hacker group also referred to as APT28, Fancy Bear, and Forest Blizzard. This group has been active for over a decade, primarily aiming to acquire login credentials from government bodies, defense contractors, and other sensitive entities to aid Russia's military intelligence operations.

From June 2024 to April 2025, the attackers established counterfeit UKR.NET login pages to illicitly gather usernames, passwords, and two-factor authentication codes from Ukrainian users. These pages were hosted via free web services such as Mocky and DNS EXIT to evade detection. The attackers distributed PDF documents containing links to these fraudulent login portals, effectively bypassing automated email security systems and sandbox tools that examine for malicious content.

Analysts from Recorded Future noted that BlueDelta altered its tactics following the disruption of their previous infrastructure by law enforcement in early 2024. The group transitioned from using compromised routers to employing proxy tunneling platforms like ngrok and Serveo to obscure the actual server locations while collecting victim credentials.

A recent credential-harvesting operation has been identified targeting users of UKR.NET, a widely-utilized Ukrainian webmail and news service.
Carter Hartwell · Thehackingpost

The operation employed customized JavaScript on fake login pages to capture user information and transmit it to attacker-controlled servers. The script also handled CAPTCHA challenges and documented victim IP addresses utilizing HTTPBin, a free API service.

In subsequent iterations, BlueDelta modified the JavaScript to disable ngrok's browser warning page, incorporating the line req.setRequestHeader("ngrok-skip-browser-warning", "1"); to avert security alerts when connecting through the proxy service. This adjustment enhanced the authenticity of the fake pages, reducing the likelihood of detection by the victims.

The operation's infrastructure consisted of multiple layers, with link-shortening services like TinyURL and Linkcuts forming the first layer, and Mocky-hosted credential-harvesting pages constituting the second. The third layer involved ngrok tunneling domains that linked to dedicated servers located in France and Canada. This multi-tiered setup posed challenges for security teams attempting to track and dismantle the attackers' operations.

Advertisement

Throughout the campaign, over 42 distinct credential-harvesting chains were identified, exemplifying the threat's scale and persistence.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories