HomeSecurityAPT28 targets UKR.net users in Ukraine in long-running phishing campaign

APT28 targets UKR.net users in Ukraine in long-running phishing campaign

The state-backed Russian threat group known as APT28 is conducting an “ongoing” credential harvesting campaign targeting users of UKR.net, a webmail and news service popular in Ukraine.

See also: Russian hackers target American engineering firm

APT28
APT28 targets UKR.net users in Ukraine in long-running phishing campaign

The activity, observed by Recorded Future 's Insikt Group between June 2024 and April 2025, builds on previous findings by the cybersecurity firm in May 2024, which described the hacking group's attacks targeting European networks with the HeadLace malware and credential harvesting pages.

APT28 is also tracked under the names BlueDelta, Fancy Bear, Forest Blizzard, FROZENLAKE, Iron Twilight, ITG05, Pawn Storm, Sednit, Sofacy, and TA422. It is believed to be linked to the General Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU).

The latest attacks are characterized by the deployment of UKR.net-themed login pages on legitimate services such as Mocky to entice recipients to enter their credentials and two-factor authentication (2FA) codes. Links to these pages are embedded in PDF documents distributed via phishing emails.

See also: Russian Curly COMrades abuses Windows Hyper-V

APT28 targets UKR.net users in Ukraine in long-running phishing campaign
APT28 targets UKR.net users in Ukraine in long-running phishing campaign

Links are shortened using services like tiny.cc or tinyurl.com. In some cases, the threat actor has been observed using subdomains created on platforms like Blogger (*.blogspot.com) to initiate a two-level redirect chain leading to the credential collection page.

The efforts are part of a broader set of phishing and credential theft operations orchestrated by the adversary since the mid-2000s, targeting government institutions, defense contractors, arms suppliers, logistics companies, and policy think tanks, in pursuit of Russia's strategic goals.

What has changed is the shift from using compromised routers to proxy tunneling services like ngrok and Serveo to capture and transmit stolen credentials and 2FA codes.

See also: Russian hackers target Ukrainian organizations with LotL strategies

APT28 targets UKR.net users in Ukraine in long-running phishing campaign

As Recorded Future reported: “The campaign highlights the GRU’s persistent interest in compromising the credentials of Ukrainian users to support intelligence-gathering operations amid Russia’s ongoing war in Ukraine.”

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS