APT28 Targets Energy and Policy Organizations in Credential Harvesting Campaign
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
APT28, also known as BlueDelta, has been linked to a series of credential harvesting attacks aimed at professionals associated with a Turkish energy and nuclear research agency, as well as a European think tank and organizations in North Macedonia and Uzbekistan. This campaign, which has been ongoing since at least February 2025, utilizes fake login pages that resemble popular services like Microsoft Outlook Web Access and Google, effectively tricking users into providing their credentials.
The attacks were characterized by the use of Turkish-language lures, indicating a strategic approach to enhance credibility among targeted audiences. Recorded Future’s Insikt Group noted that these efforts reflect a sustained interest in organizations involved in energy research and defense cooperation, aligning with Russian intelligence priorities.
In February and September 2025, APT28 employed phishing emails containing shortened links that redirected victims to decoy documents before leading them to spoofed login pages. The attack chain cleverly disguises the phishing attempt by displaying legitimate documents from credible sources, such as a publication from the Gulf Research Center and a policy briefing from the ECCO climate change think tank.
APT28 has also been observed conducting other credential harvesting campaigns, including one in June 2025 that mimicked a Sophos VPN password reset page and another in September 2025 that falsely warned users about expired passwords. These campaigns leveraged hosting services like InfinityFree and Byet Internet Services to create the phishing pages.
The group’s consistent use of legitimate internet services for hosting phishing content highlights a troubling trend in cyber threats, as it allows them to bypass traditional security measures. This method of credential harvesting is not only low-cost but also highly effective in gathering sensitive information.
Implications for Users and Organizations
For everyday users and organizations, the tactics employed by APT28 serve as a reminder of the importance of vigilance against phishing attempts. Users should be cautious of unsolicited emails, especially those containing links or requests for credentials, as they may lead to fake login pages.
Organizations should consider implementing multi-factor authentication (MFA) to add an extra layer of security against unauthorized access. Regular training on recognizing phishing attempts can also help mitigate risks associated with these types of attacks.
Monitoring for unusual account activity and ensuring that all software is up to date can further protect against credential harvesting efforts. By understanding the methods used by threat actors like APT28, users and organizations can better prepare themselves against potential cyber threats.
Key Takeaways
- Be cautious of unsolicited emails requesting credentials or containing links.
- Implement multi-factor authentication (MFA) for added security on accounts.
- Regularly train staff on recognizing phishing attempts and suspicious emails.
- Monitor accounts for unusual activity and respond promptly to any alerts.
- Keep all software and security measures up to date to protect against vulnerabilities.
Key Terms & Concepts
- APT28: In this article, APT28 refers to a Russian state-sponsored group involved in cyber espionage and credential harvesting.
- Credential Harvesting: Credential harvesting is a cyber attack method where attackers collect user credentials through deceptive means, such as phishing.
- Phishing: Phishing is a technique used by cybercriminals to trick individuals into providing sensitive information by masquerading as a trustworthy entity.
- Multi-Factor Authentication (MFA): MFA is a security measure that requires more than one form of verification to access an account, enhancing protection against unauthorized access.
- Webhooks: Webhooks are automated messages sent from apps when something happens, often used in phishing to capture data from unsuspecting users.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.