FancyBear Server Leak Exposes Stolen Credentials, 2FA Secrets, NATO Targets
Recent findings have revealed a significant operational security lapse by FancyBear, leading to the exposure of a Russian espionage server. This server contained a wealth of sensitive information, including stolen credentials and 2FA secrets, and…
Recent findings have revealed a significant operational security lapse by FancyBear, leading to the exposure of a Russian espionage server. This server contained a wealth of sensitive information, including stolen credentials and 2FA secrets, and provided insight into ongoing targeting activities against European government and military networks.
Researchers identified an open directory on a Command and Control (C2) server located at the IP address 203.161.50[.]145. This server is affiliated with APT28/FancyBear. The open directory contained source code, payloads, logs, and exfiltrated data, offering substantial visibility into the operations of FancyBear.
Over 2,800 exfiltrated emails and 240 credential sets, including TOTP 2FA secrets, were discovered. Approximately 140 persistent forwarding rules and over 11,500 harvested contact addresses were identified. Victim entities included government and military organizations from Ukraine, Romania, Bulgaria, Greece, Serbia, and North Macedonia.
The infrastructure continued to operate, despite exposure, for approximately 500 days into early 2026. This contradicts the conventional understanding that Advanced Persistent Threat (APT) infrastructure is swiftly rotated once compromised.
Recent findings have revealed a significant operational security lapse by FancyBear, leading to the exposure of a Russian espionage server.
The server's open directories revealed various tools and logs, providing defenders with the opportunity to analyze FancyBear's toolkit. The toolkit exploits vulnerabilities in webmail platforms such as Roundcube and SquirrelMail, using JavaScript payloads for malicious activities.
Modules like keyTwoAuth.js target the twofactor_gauthenticator plugin to extract TOTP seeds and recovery codes. The module addRedirectMailBox.js leverages Roundcube's ManageSieve integration to implement persistent email forwarding rules.
The exposed infrastructure also included phishing email campaigns utilizing domains like zhblz[.]com to deliver malicious payloads.
Geopolitical and Defensive Implications
The campaign primarily targeted states involved in military activities related to Ukraine, aligning with Russia's strategic interests. The incident emphasizes the necessity for enhanced security measures on webmail platforms and highlights the potential for simple operational security mistakes by sophisticated threat actors.
Defensive measures should focus on securing webmail servers, hardening plugins, and monitoring for specific indicators such as the identified domains and IP addresses.
Based on reporting by GBHackers.
