#FancyBear
AF attack #39 is Mariana for FancyBear! I don’t think they have a BlueSky account.
July 28, 2026 at 8:20 PM
Ni sous le format cyber-attaque? NoName057, FancyBear, etc c'est juste des preuves d'amour tumul tueuses?
October 23, 2025 at 8:01 PM
He looks more like a hacker from FancyBear or suchlike. But perhaps he moonlights :)
May 21, 2026 at 10:59 PM
Oooooh I just found a very old screenshot of the wonderful text adventure BEARS thread between @ethanmarcotte.com and @wil.to. It remains one of my favourite internet things.
May 13, 2026 at 8:10 PM
😆Within 12 hours of APT-28🇷🇺 boasting publicly
@anonymousbsns.bsky.social
Had the top members doxed & located
justpaste.it/fv4q3
and within 24 hours
@youranonfrance.bsky.social doxed FancyBear🐻 & NoName too!😆🔥
justpaste.it/jxfzy
🇫🇷 Viva la France 🇫🇷
May 15, 2025 at 2:11 PM
After Hunt found an open directory hosting APT28's Roundcube exploit kit, Ctrl-Alt-Intel also found a 2nd open directory on the same server, this one with the "C2 source code, additional payloads, telemetry logs, exfiltrated data and evidence of further campaigns."

ctrlaltintel.com/threat%20res...
FancyBear Exposed: Major OPSEC Blunder Inside Russian Espionage Ops
FancyBear’s OPSEC failure gives Ctrl-Alt-Intel rare visibility inside Russian espionage operations
ctrlaltintel.com
March 17, 2026 at 12:48 PM
Dus, Putin heeft weer even uitgelegd hoe Trump ook alweer aan zijn presidentschap kwam? #CozyBear #FancyBear
Die man zit heel diep in de zakken van Putin...
October 20, 2025 at 9:21 AM
NEW POD!! CISA’s multi-agency APT28/FancyBear advisory (solid intel, sloppy YARA); Sekoia finds 5K+ hijacked edge devices moonlighting as Chinese honeypots; Signal’s move to block Windows Recall screenshots, and an Akamai/Microsoft vuln-disclosure debate @craiu.bsky.social @jags.bsky.social 👇
May 23, 2025 at 7:43 PM
Today, we released new @RecordedFuture research detailing BlueDelta’s expanded credential-harvesting activity observed between February and September 2025. #BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #ITG05 #PawnStorm #Sednit #Sofacy #TA422 (1/5) www.recordedfuture.com/research/gru...
GRU-Linked BlueDelta Evolves Credential Harvesting
Insikt Group reveals how GRU-linked BlueDelta evolved credential-harvesting campaigns targeting government, energy, and research organizations across Europe and Eurasia.
www.recordedfuture.com
January 7, 2026 at 3:39 PM
A Phishing Trip with Fancy Bear

Hands-on analysis of a real APT28 attack chain — phishing email → payload → persistence → C2.
Interactive platform, real artefacts, free tools only. Beginner-friendly.

#FancyBear #APT28 #MalwareAnalysis
September 4, 2026 at 8:22 AM
February 17, 2025 at 10:32 AM
Whoa, Fancy Bear left some of their infrastructure exposed by accident, and it got mined to hell by a threat intel org.
ctrlaltintel.com/threat%20res...
FancyBear Exposed: Major OPSEC Blunder Inside Russian Espionage Ops
FancyBear’s OPSEC failure gives Ctrl-Alt-Intel rare visibility inside Russian espionage operations
ctrlaltintel.com
March 17, 2026 at 7:04 PM
Story builds on the data obtained by Ctrl-Alt-Intel, a collective of cyber researchers.

Their blog post is here: ctrlaltintel.com/research/Fan...
FancyBear Exposed: Major OPSEC Blunder Inside Russian Espionage Ops
FancyBear’s OPSEC failure gives Ctrl-Alt-Intel rare visibility inside Russian espionage operations
ctrlaltintel.com
April 15, 2026 at 4:32 PM
⚠️ Critical #XSS flaw actively exploited in Zimbra Collaboration Suite, putting over 129,000 servers at risk. Researchers suspect involvement of #Sednit (aka Fancy Bear).

Read: hackread.com/zimbra-cve-2...

#CyberSecurity #Vulnerability #FancyBear #Zimbra
Zimbra CVE-2024-27443 XSS Flaw Hits 129K Servers, Sednit Suspected
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
May 24, 2025 at 2:46 PM
FancyBear, and others. This group hacked the computer systems of the US Democratic Party in 2016 - the largest and most famous documented case of foreign hackers interfering in the electoral process. By the way, InformNapalm volunteers helped expose that ART28 was behind the interference
May 23, 2025 at 3:05 AM
#day46 #prompt #bearinasuit
Pretty straightforward but my god this little guy is so #cute! realized I messed up the hashtag count.
#art #artist #bear #lineart #ink #suit #dressedup #suit #fancy #fancybear #animal #silly #shading #tie #briefcase
February 13, 2026 at 6:05 PM
Today, we released new @RecordedFuture research detailing BlueDelta’s sustained credential-harvesting campaign targeting UKR.NET users between June 2024 and April 2025. www.recordedfuture.com/research/blu...
#BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #PawnStorm #Sednit #Sofacy (1/5)
BlueDelta’s Persistent Campaign Against UKR.NET
Discover how Russia’s BlueDelta targets UKR.NET users with advanced credential-harvesting campaigns, evolving tradecraft, and multi-stage phishing techniques.
www.recordedfuture.com
December 17, 2025 at 3:46 PM
⚠️ New threat actor on the radar ⚠️

🥷🏻 AiLock
🗓️ added on March 03, 2026 (first identified April 2025)

🥢 Overview
Emerging ransomware group that publicly markets itself as "AI-assisted." Active since early 2025, it is suspected of having ties to the Russian state-associated threat actor #FancyBear
March 3, 2026 at 6:01 PM
I dunno, maybe?

On a unrelated topic:

🚨ATTENTION!🚨 You've been selected to WIN BIG! 🏆 Click here NOW to claim your FREE all-inclusive luxury vacation to Tenerife! 🌴🏨 Only 10 spots left! Don't miss out! No purchase necessary. Winners announced daily. 💨 182371.dhggay.ru/~fancybear/a...
December 6, 2024 at 6:19 PM
FancyBear Exposed: Major OPSEC Blunder Inside Russian Espionage Ops ctrlaltintel.com/threat%20res...
FancyBear Exposed: Major OPSEC Blunder Inside Russian Espionage Ops
FancyBear’s OPSEC failure gives Ctrl-Alt-Intel rare visibility inside Russian espionage operations
ctrlaltintel.com
March 27, 2026 at 6:42 PM
Building on initial findings, Ctrl-Alt-Intel discovered a second open-directory on the same server. One that contained FancyBears C2 source code, payloads, exfiltrated data and evidence of further campaigns

ctrlaltintel.com/research/Fan...

#infosec #cybersecurity #threatintel #malware
FancyBear Exposed: Major OPSEC Blunder Inside Russian Espionage Ops
FancyBear’s OPSEC failure gives Ctrl-Alt-Intel rare visibility inside Russian espionage operations
ctrlaltintel.com
May 23, 2026 at 8:50 AM
📢 Russian-linked #ForestBlizzard hackers hijack home routers for global surveillance, as Microsoft warns that thousands of devices are compromised to intercept traffic and sensitive data.

Read: hackread.com/russian-fore...

#CyberSecurity #Hacking #Russia #FancyBear #Routers
Russian Forest Blizzard Hackers Hijack Home Routers for Global Spying
Microsoft Threat Intelligence reveals how Russian hacking group Forest Blizzard uses home routers for DNS hijacking and spying.
hackread.com
April 8, 2026 at 11:37 AM