APT28 Targets Ukrainian UKR-net Users in Credential Phishing Campaign
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
APT28, also known as BlueDelta and Fancy Bear, has been linked to a long-running credential phishing campaign aimed at users of UKR[.]net, a popular webmail service in Ukraine. This activity was tracked by Recorded Future’s Insikt Group from June 2024 to April 2025. The attackers employed UKR[.]net-themed login pages hosted on legitimate services, enticing users to enter their credentials and 2FA codes.
The phishing emails contained links to these malicious pages, often shortened using services like tiny[.]cc or tinyurl[.]com. In some instances, APT28 utilized subdomains on platforms like Blogger to create a redirection chain leading to the credential harvesting sites. This approach indicates a shift in tactics, moving from compromised routers to using proxy tunneling services for credential capture.
Historically, APT28 has targeted various sectors, including government institutions and defense contractors, to further Russia’s strategic objectives. The current campaign highlights their persistent interest in Ukrainian user credentials, which is likely motivated by the ongoing war in Ukraine.
Recorded Future noted that the use of free hosting and anonymized tunneling reflects an adaptive response to previous infrastructure takedowns by Western cybersecurity agencies. This adaptability underscores the evolving nature of cyber threats and the need for vigilance among users.
For everyday users, recognizing phishing attempts can be challenging, especially when they appear to come from legitimate services. Users should be cautious of unsolicited emails requesting login information or 2FA codes, as these could be part of similar phishing schemes.
Organizations, particularly those operating in sensitive sectors, should enhance their security measures by implementing robust email filtering and user education programs. Regular training on recognizing phishing attempts can significantly reduce the risk of falling victim to such attacks.
Key Takeaways
- Be cautious of emails requesting login information or 2FA codes, especially if they appear to come from legitimate services.
- Implement robust email filtering to detect and block phishing attempts targeting your organization.
- Educate employees about recognizing phishing emails and the importance of verifying links before clicking.
- Monitor accounts for unusual login attempts or unauthorized access, especially if you use services like UKR[.]net.
- Consider using multi-factor authentication (MFA) to add an extra layer of security to your accounts.
Key Terms & Concepts
- APT28: In this article, APT28 refers to a Russian state-sponsored threat actor known for cyber espionage and credential theft.
- UKR[.]net: UKR[.]net is a webmail and news service popular in Ukraine, targeted by phishing campaigns.
- Credential Harvesting: Credential harvesting is a cyber attack method aimed at collecting user login information, including usernames and passwords.
- 2FA: 2FA, or two-factor authentication, is a security process that requires two forms of identification before granting access to an account.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.