GRU-linked actor expands credential harvesting
In 2025 Recorded Future reported that the GRU-linked threat actor BlueDelta, also known as APT28, has significantly expanded its credential-harvesting operations. Campaigns imitate login pages for Microsoft Outlook Web Access, Google and Sophos VPN, and the actor abuses free hosting and tunnelling services such as Webhook.site, InfinityFree, Byet and ngrok to serve the spoofed pages. Legitimate PDF lure documents help evade email security, and custom JavaScript captures entered data before auto-redirecting the victim to the real site.
What this means for your organisation
Targeting patterns point at researchers and institutions in Europe, with intelligence collection as the goal. The method is technically simple but effective: because the links point to legitimate, well-reputed services, they often pass filters. Redirecting the victim to the genuine login page means few people report anything, and the organisation notices only when the account is used. Passwords alone are therefore not adequate protection against this kind of campaign.
Berigo recommends
- Deploy phishing-resistant multi-factor authentication, for example FIDO2 keys, on email, VPN and administrator accounts.
- Monitor sign-ins from unusual locations and new devices, and alert on session reuse.
- Consider blocking or flagging links to known tunnelling and free hosting services in email.
- Give staff in exposed roles concrete training on lure documents with genuine PDFs attached, not only generic phishing awareness.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch