BlueDelta , a Russian state-backed threat group linked to the country's military intelligence agency (known as the GRU ), significantly expanded its credential-sniffing operations throughout 2025 .
See also: CISA: Microsoft Office and HPE OneView vulnerabilities in the KEV Catalog

Between February and September, the group carried out multiple phishing campaigns aimed at tricking users of Microsoft Outlook Web Access, Google , and Sophos VPNinto revealing their login credentials. This evolving threat demonstrates the group’s continued focus on collecting credentials from government officials, energy workers, and research professionals across Europe and Eurasia.
These attacks are a clear evolution of BlueDelta's long-standing operational tactic, which has targeted sensitive organizations since the mid-2000s 2000.
The group focuses primarily on entities related to energy research, defense cooperation , and government communications networks.
See also: PoC exploit for CVE-2025-38352 vulnerability in the Android/Linux kernel

Recent campaigns reveal an increased level of sophistication, as BlueDelta combines multiple attack stages, customized malicious code, and highly convincing decoy documents in order to bypass security measures and boost victims' trust.
Analysts at Recorded Future identified the malware after the second phase of development, revealing the technical mechanisms behind each attack.
Researchers found that BlueDelta relies heavily on free hosting services, such as Webhook.site, InfinityFree, Byet Internet Services , and ngrok, to host fake login pages and automatically collect stolen credentials. This infrastructure strategy keeps operational costs low while offering flexibility through temporary and easily replaceable services.
See also: Veeam: New vulnerabilities expose backup servers to RCE attacks

The team's continued refinement of these techniques demonstrates a sophisticated understanding of user psychology and web browser behavior, allowing BlueDelta to maintain high success rates in credential theft while avoiding detection.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
