APT28 ran a long campaign against Ukrainian webmail users

Between June 2024 and April 2025, Recorded Future's Insikt Group tracked a persistent credential-harvesting campaign by the threat actor APT28, also known as BlueDelta, aimed at users of the Ukrainian webmail service UKR.NET. The actor distributed malicious PDF lures linking to fake UKR.NET login pages hosted on free and proxy tunnelling services, capturing usernames, passwords, two-factor codes and other sensitive data. The infrastructure was adapted over time to evade detection. The activity reflects the GRU-linked group's long-standing credential-theft tradecraft and Russian intelligence collection amid the conflict in Ukraine.

What this means for your organisation

The campaign shows that two-factor codes typed into a web page can be captured in real time. This is not a Ukrainian special case; the technique works just as well elsewhere. Organisations with operations, staff or suppliers in Ukraine, and firms in defence, energy and logistics, should assume they fall within the same field of interest.

Berigo recommends

  • Move from one-time codes to phishing-resistant methods such as passkeys or hardware keys.
  • Assess your own exposure based on sector and geographic ties, and document the assessment.
  • Apply stricter access requirements for staff and partners in exposed regions.
  • Rehearse how you handle a hijacked mailbox, including notifying recipients who received mail from it.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch