BlueDelta Hackers Target Users of Popular Ukrainian Webmail and News Service
Between June 2024 and April 2025, the Russian state-sponsored threat group BlueDelta conducted a sustained credential-harvesting campaign targeting users of UKR.NET, a widely used webmail and news service in Ukraine.
Between June 2024 and April 2025, the Russian state-sponsored threat group BlueDelta conducted a sustained credential-harvesting campaign targeting users of UKR.NET, a widely used webmail and news service in Ukraine.
Research by Recorded Future's Insikt Group indicates the operation marks a significant escalation in efforts by this GRU-linked actor to compromise Ukrainian user credentials for intelligence-gathering amid ongoing military operations in Ukraine.
Insikt Group identified the deployment of over 42 credential-harvesting chains across various free web services during the investigation. BlueDelta utilized Mocky API services to host fake UKR.NET login portals and employed free hosting providers, including DNS EXIT, Byet Internet Services, and ngrok's reverse proxy tunneling infrastructure, to gather usernames, passwords, and two-factor authentication codes from victims.
The threat group demonstrated significant technical refinement by employing a multi-tiered architecture using free domains, link-shortening services, and proxy tunnels to obscure the actual locations of its command-and-control servers. The campaign involved custom JavaScript to exfiltrate credentials, relay CAPTCHA responses, and capture victim IP addresses through HTTPBin services.
One notable tactic involved distributing PDF lures disguised as account security notifications from UKR.NET, designed to bypass email filtering and sandbox detection mechanisms. These documents informed targets of suspicious account activity and directed them to embedded links for password resets.
Insikt Group identified the deployment of over 42 credential-harvesting chains across various free web services during the investigation.
From March to April 2025, Insikt Group detected updates to BlueDelta's infrastructure, including new tier-three and previously unseen tier-four components. The group transitioned from DNS EXIT domains to ngrok's free subdomains and operated dedicated servers in France and Canada to handle credential exfiltration and relay operations. Analysis revealed persistent operational presence through SSH access on standard ports and custom HTTP services.
BlueDelta's strategy included the use of typosquat domains such as ukrinet[.]com and ukrainnet[.]com to maintain backup infrastructure. An innovation involved adding ngrok-skip-browser-warning HTTP headers to JavaScript code to disable ngrok's safety warnings that could alert users to proxy service presence.
BlueDelta's focus on Ukrainian user credentials aligns with documented GRU intelligence requirements. Organizations serving Ukrainian users are advised to implement multi-factor authentication, deny-list non-critical free hosting services, and conduct regular security awareness training addressing fake login portals and account-themed lures.
The group has targeted government institutions, defense contractors, logistics firms, and policy think tanks for over a decade, leveraging credential theft for multi-phase espionage operations supporting Russia's strategic interests.
Security researchers anticipate that BlueDelta will continue credential-harvesting operations through 2026, relying on low-cost, anonymous web infrastructure while diversifying hosting and redirection platforms. The campaign highlights the persistent threat of state-sponsored credential theft as a cost-effective method for initial access and intelligence collection. Organizations must remain vigilant through continuous threat intelligence monitoring and incident response preparedness.
Based on reporting by GBHackers.
