Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

BlueDelta Hackers Target Users of Popular Ukrainian Webmail and News Service

Between June 2024 and April 2025, the Russian state-sponsored threat group BlueDelta conducted a sustained credential-harvesting campaign targeting users of UKR.NET, a widely used webmail and news service in Ukraine.

Between June 2024 and April 2025, the Russian state-sponsored threat group BlueDelta conducted a sustained credential-harvesting campaign targeting users of UKR.NET, a widely used webmail and news service in Ukraine.

Research by Recorded Future's Insikt Group indicates the operation marks a significant escalation in efforts by this GRU-linked actor to compromise Ukrainian user credentials for intelligence-gathering amid ongoing military operations in Ukraine.

Insikt Group identified the deployment of over 42 credential-harvesting chains across various free web services during the investigation. BlueDelta utilized Mocky API services to host fake UKR.NET login portals and employed free hosting providers, including DNS EXIT, Byet Internet Services, and ngrok's reverse proxy tunneling infrastructure, to gather usernames, passwords, and two-factor authentication codes from victims.

The threat group demonstrated significant technical refinement by employing a multi-tiered architecture using free domains, link-shortening services, and proxy tunnels to obscure the actual locations of its command-and-control servers. The campaign involved custom JavaScript to exfiltrate credentials, relay CAPTCHA responses, and capture victim IP addresses through HTTPBin services.

One notable tactic involved distributing PDF lures disguised as account security notifications from UKR.NET, designed to bypass email filtering and sandbox detection mechanisms. These documents informed targets of suspicious account activity and directed them to embedded links for password resets.

Insikt Group identified the deployment of over 42 credential-harvesting chains across various free web services during the investigation.
Harper Fairbanks · Thehackingpost

From March to April 2025, Insikt Group detected updates to BlueDelta's infrastructure, including new tier-three and previously unseen tier-four components. The group transitioned from DNS EXIT domains to ngrok's free subdomains and operated dedicated servers in France and Canada to handle credential exfiltration and relay operations. Analysis revealed persistent operational presence through SSH access on standard ports and custom HTTP services.

BlueDelta's strategy included the use of typosquat domains such as ukrinet[.]com and ukrainnet[.]com to maintain backup infrastructure. An innovation involved adding ngrok-skip-browser-warning HTTP headers to JavaScript code to disable ngrok's safety warnings that could alert users to proxy service presence.

BlueDelta's focus on Ukrainian user credentials aligns with documented GRU intelligence requirements. Organizations serving Ukrainian users are advised to implement multi-factor authentication, deny-list non-critical free hosting services, and conduct regular security awareness training addressing fake login portals and account-themed lures.

Advertisement

The group has targeted government institutions, defense contractors, logistics firms, and policy think tanks for over a decade, leveraging credential theft for multi-phase espionage operations supporting Russia's strategic interests.

Security researchers anticipate that BlueDelta will continue credential-harvesting operations through 2026, relying on low-cost, anonymous web infrastructure while diversifying hosting and redirection platforms. The campaign highlights the persistent threat of state-sponsored credential theft as a cost-effective method for initial access and intelligence collection. Organizations must remain vigilant through continuous threat intelligence monitoring and incident response preparedness.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories