HomeSecurityBlueDelta launches attacks to steal login credentials

BlueDelta launches attacks to steal login credentials

BlueDelta , a Russian state-backed threat group linked to the country's military intelligence agency (known as the GRU ), significantly expanded its credential-sniffing operations throughout 2025 .

See also: CISA: Microsoft Office and HPE OneView vulnerabilities in the KEV Catalog

BlueDelta

Between February and September, the group carried out multiple phishing campaigns aimed at tricking users of Microsoft Outlook Web Access, Google , and Sophos VPNinto revealing their login credentials. This evolving threat demonstrates the group’s continued focus on collecting credentials from government officials, energy workers, and research professionals across Europe and Eurasia.

These attacks are a clear evolution of BlueDelta's long-standing operational tactic, which has targeted sensitive organizations since the mid-2000s 2000.

The group focuses primarily on entities related to energy research, defense cooperation , and government communications networks.

See also: PoC exploit for CVE-2025-38352 vulnerability in the Android/Linux kernel

BlueDelta launches attacks to steal login credentials

Recent campaigns reveal an increased level of sophistication, as BlueDelta combines multiple attack stages, customized malicious code, and highly convincing decoy documents in order to bypass security measures and boost victims' trust.

Analysts at Recorded Future identified the malware after the second phase of development, revealing the technical mechanisms behind each attack.

Researchers found that BlueDelta relies heavily on free hosting services, such as Webhook.site, InfinityFree, Byet Internet Services , and ngrok, to host fake login pages and automatically collect stolen credentials. This infrastructure strategy keeps operational costs low while offering flexibility through temporary and easily replaceable services.

See also: Veeam: New vulnerabilities expose backup servers to RCE attacks

BlueDelta launches attacks to steal login credentials

The team's continued refinement of these techniques demonstrates a sophisticated understanding of user psychology and web browser behavior, allowing BlueDelta to maintain high success rates in credential theft while avoiding detection.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS