BlueDelta Hackers Attacking Users of Widely Used Ukrainian Webmail and News Service
A recent credential-harvesting operation has been identified targeting users of UKR.NET, a widely-utilized Ukrainian webmail and news service.
A recent credential-harvesting operation has been identified targeting users of UKR.NET, a widely-utilized Ukrainian webmail and news service.
The campaign is attributed to BlueDelta, recognized as a Russian state-sponsored hacker group also referred to as APT28, Fancy Bear, and Forest Blizzard. This group has been active for over a decade, primarily aiming to acquire login credentials from government bodies, defense contractors, and other sensitive entities to aid Russia's military intelligence operations.
From June 2024 to April 2025, the attackers established counterfeit UKR.NET login pages to illicitly gather usernames, passwords, and two-factor authentication codes from Ukrainian users. These pages were hosted via free web services such as Mocky and DNS EXIT to evade detection. The attackers distributed PDF documents containing links to these fraudulent login portals, effectively bypassing automated email security systems and sandbox tools that examine for malicious content.
Analysts from Recorded Future noted that BlueDelta altered its tactics following the disruption of their previous infrastructure by law enforcement in early 2024. The group transitioned from using compromised routers to employing proxy tunneling platforms like ngrok and Serveo to obscure the actual server locations while collecting victim credentials.
A recent credential-harvesting operation has been identified targeting users of UKR.NET, a widely-utilized Ukrainian webmail and news service.
The operation employed customized JavaScript on fake login pages to capture user information and transmit it to attacker-controlled servers. The script also handled CAPTCHA challenges and documented victim IP addresses utilizing HTTPBin, a free API service.
In subsequent iterations, BlueDelta modified the JavaScript to disable ngrok's browser warning page, incorporating the line req.setRequestHeader("ngrok-skip-browser-warning", "1"); to avert security alerts when connecting through the proxy service. This adjustment enhanced the authenticity of the fake pages, reducing the likelihood of detection by the victims.
The operation's infrastructure consisted of multiple layers, with link-shortening services like TinyURL and Linkcuts forming the first layer, and Mocky-hosted credential-harvesting pages constituting the second. The third layer involved ngrok tunneling domains that linked to dedicated servers located in France and Canada. This multi-tiered setup posed challenges for security teams attempting to track and dismantle the attackers' operations.
Throughout the campaign, over 42 distinct credential-harvesting chains were identified, exemplifying the threat's scale and persistence.
Based on reporting by Cyber Security News.
