#BlueDelta
GRU's BlueDelta Espionage Campaigns Across Europe. go.recordedfuture.com/hubfs/report...
June 19, 2024 at 7:17 AM
Today, we released new @RecordedFuture research detailing BlueDelta’s expanded credential-harvesting activity observed between February and September 2025. #BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #ITG05 #PawnStorm #Sednit #Sofacy #TA422 (1/5) www.recordedfuture.com/research/gru...
GRU-Linked BlueDelta Evolves Credential Harvesting
Insikt Group reveals how GRU-linked BlueDelta evolved credential-harvesting campaigns targeting government, energy, and research organizations across Europe and Eurasia.
www.recordedfuture.com
January 7, 2026 at 3:39 PM
APT28 has "no fewer than 28 aliases"

Nice job, infosec!

blog.sekoia.io/apt28-operat...
September 16, 2025 at 4:14 PM
Today Insikt Group released new research on BlueDelta’s initial access campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye, using diplomatic-themed docs to deliver the backdoor HOOKEDGE. Check out the report here: www.recordedfuture.com/research/blu...
BlueDelta Targets Defense and Diplomacy with HOOKEDGE
Discover how the Russian state-sponsored threat group BlueDelta is using the HOOKEDGE backdoor to target defense and diplomatic organizations across Europe
www.recordedfuture.com
August 27, 2026 at 9:50 PM
Insikt Group has identified a series of BlueDelta (APT28/Fancy Bear/Forest Blizzard) initial access campaigns targeting government & diplomatic organizations in Romania, Spain & Turkey. The campaigns deliver the HOOKEDGE backdoor using diplomatic-themed lures. www.recordedfuture.com/research/blu...
August 28, 2026 at 8:32 AM
Russian state-sponsored hackers, BlueDelta, are targeting Ukrainian webmail users with sophisticated credential theft campaigns. Stay vigilant and secure your accounts. #CyberSecurity #BlueDelta #Ukraine Link: thedailytechfeed.com/bluedelta-la...
December 20, 2025 at 4:22 PM
Giving a quick update on my ongoing Pokémon Mystery Dungeon rom hack project.

The hack as of yesterday is playable from start to finish! Its got around an hour-ish worth of content if you're reading the dialogue.

Here's the first 8-10 minutes of the hack! Release Date TBD.

youtu.be/mTudmWf9SyM
Future's Gifts Teaser
YouTube video by BlueDelta
youtu.be
February 1, 2025 at 10:49 PM
Today, we released new @RecordedFuture research detailing BlueDelta’s sustained credential-harvesting campaign targeting UKR.NET users between June 2024 and April 2025. www.recordedfuture.com/research/blu...
#BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #PawnStorm #Sednit #Sofacy (1/5)
BlueDelta’s Persistent Campaign Against UKR.NET
Discover how Russia’s BlueDelta targets UKR.NET users with advanced credential-harvesting campaigns, evolving tradecraft, and multi-stage phishing techniques.
www.recordedfuture.com
December 17, 2025 at 3:46 PM
(Thanks to Bruce Sterling.)

#cybersec

*This is how the pros get it done nowadays -- "the Russian GRU 85th GTsSS, military unit 26165—commonly known in the cybersecurity community as APT28, Fancy Bear, Forest Blizzard, and BlueDelta."
Russian GRU Targeting Western Logistics Entities and Technology Companies | CISA
Executives and network defenders should recognize the elevated threat of unit 26165 targeting, increase monitoring and threat hunting for known TTPs and IOCs, and posture network defenses with a presu...
www.cisa.gov
May 22, 2025 at 6:33 AM
Recorded Future’s Insikt Group tracks GRU-linked BlueDelta credential theft, mimicking OWA, Google and Sophos VPN portals. Targets include a Turkish energy & nuclear research agency, a European think tank, and organizations in North Macedonia & Uzbekistan. www.recordedfuture.com/research/gru...
January 8, 2026 at 9:05 AM
July 30, 2026 at 7:45 PM
-Analysis of Bauman leak
-Russian APT uses malicious prompts to prevent AI from analyzing malware
-New Dark Caracal, TortoiseShell, and BlueDelta ops
-DPRK remote workers expand beyond IT jobs
-New ZBT router backdoors
-PaperCut zero-day
-GPUThor Rowhammer attack
-Gitea bug exploited in the wild
August 28, 2026 at 11:58 AM
BlueDelta Hackers attacking Users of widely Used Ukrainian Webmail and News Service:

cybersecuritynews.com/bluedelta-ha...
December 22, 2025 at 6:06 AM
Russian BlueDelta hackers ran phishing campaign against Ukrainian webmail users https://therecord.media/russian-bluedelta-hackers-ran-phishing-ukraine-webmail
Russian BlueDelta hackers ran phishing campaign against Ukrainian webmail users
Russian BlueDelta hackers ran phishing campaign against Ukrainian webmail users
therecord.media
December 17, 2025 at 7:23 PM
-Leak exposes APT35 bureaucracy
-Prince of Persia APT returns
-ForumTroll targets Russian scholars
-APT reports on Arcane Werewolf, BlueDelta, BlindEagle, LongNosedGoblin
-React2Shell is now used for ransomware
-FreeBSD and HPE RCEs
-New DMA attacks
-Fewer critical bugs in 2024
December 19, 2025 at 9:22 AM
A new TAG-110 report, including victimology and recent C2 infrastructure, has just landed. #TAG110 #BlueDelta #APT28 www.recordedfuture.com/research/rus...
Russia-Aligned TAG-110 Targets Asia and Europe with HATVIBE and CHERRYSPY
TAG-110, a Russia-aligned threat group, targets organizations across Asia and Europe using HATVIBE and CHERRYSPY malware for espionage. Learn how Recorded Future's analysis uncovers the group’s tactic...
www.recordedfuture.com
November 21, 2024 at 3:38 PM
New research from Insikt Group on a phishing campaign targeting Tajikistan attributed to TAG-110, a Russia-aligned threat actor, which overlaps with UAC-0063 and has been associated with APT28 (BlueDelta): www.recordedfuture.com/research/rus...
TAG-110 Targets Tajikistan: New Macro Word Documents Phishing Tactics
Russia-aligned TAG-110 shifts to .dotm phishing lures in a 2025 campaign against Tajikistan’s public sector, advancing cyber-espionage in Central Asia.
www.recordedfuture.com
May 22, 2025 at 5:02 PM
BlueDelta Hackers Attacking Microsoft OWA, Google, and Sophos VPN Users to Steal Logins
BlueDelta Hackers Attacking Microsoft OWA, Google, and Sophos VPN Users to Steal Logins
cybersecuritynews.com
January 8, 2026 at 7:43 AM
More on this!

“…targeting human rights groups, private security companies, and state and educational institutions in Central Asia, East Asia, and Europe...”

“…likely linked to the Russian cyber-espionage group BlueDelta, also known as APT28 or Fancy Bear.”

therecord.media/central-asia...
November 23, 2024 at 6:33 PM
Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations

BlueDelta (APT28) uses webhook.site and Microsoft Edge to hide HOOKEDGE espionage traffic targeting European governments. Recorded Future’s Insikt Group documented a campaign by BlueDelt…
#hackernews #microsoft #news
Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations
BlueDelta (APT28) uses webhook.site and Microsoft Edge to hide HOOKEDGE espionage traffic targeting European governments. Recorded Future’s Insikt Group documented a campaign by BlueDelta, the Russian GRU-linked group that overlaps with the group APT28, running an entire espionage operation against European government targets using webhook.site, a service built for developers to test HTTP requests, as […]
securityaffairs.com
August 29, 2026 at 1:17 PM
Russian BlueDelta hackers ran phishing campaign against Ukrainian webmail users therecord.media/russian-blue...
Russian BlueDelta hackers ran phishing campaign against Ukrainian webmail users
Researchers said the campaign likely aimed to collect sensitive information from Ukrainian users in support of broader Russian intelligence objectives.
therecord.media
December 24, 2025 at 4:12 PM