The state-backed Russian threat group known as APT28 is conducting an “ongoing” credential harvesting campaign targeting users of UKR.net, a webmail and news service popular in Ukraine.
See also: Russian hackers target American engineering firm

The activity, observed by Recorded Future 's Insikt Group between June 2024 and April 2025, builds on previous findings by the cybersecurity firm in May 2024, which described the hacking group's attacks targeting European networks with the HeadLace malware and credential harvesting pages.
APT28 is also tracked under the names BlueDelta, Fancy Bear, Forest Blizzard, FROZENLAKE, Iron Twilight, ITG05, Pawn Storm, Sednit, Sofacy, and TA422. It is believed to be linked to the General Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU).
The latest attacks are characterized by the deployment of UKR.net-themed login pages on legitimate services such as Mocky to entice recipients to enter their credentials and two-factor authentication (2FA) codes. Links to these pages are embedded in PDF documents distributed via phishing emails.
See also: Russian Curly COMrades abuses Windows Hyper-V

Links are shortened using services like tiny.cc or tinyurl.com. In some cases, the threat actor has been observed using subdomains created on platforms like Blogger (*.blogspot.com) to initiate a two-level redirect chain leading to the credential collection page.
The efforts are part of a broader set of phishing and credential theft operations orchestrated by the adversary since the mid-2000s, targeting government institutions, defense contractors, arms suppliers, logistics companies, and policy think tanks, in pursuit of Russia's strategic goals.
What has changed is the shift from using compromised routers to proxy tunneling services like ngrok and Serveo to capture and transmit stolen credentials and 2FA codes.
See also: Russian hackers target Ukrainian organizations with LotL strategies

As Recorded Future reported: “The campaign highlights the GRU’s persistent interest in compromising the credentials of Ukrainian users to support intelligence-gathering operations amid Russia’s ongoing war in Ukraine.”
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
