Wednesday , June 24 2026
BlueDelta

BlueDelta Target Sophos VPN, Google, Microsoft OWA to Steal Credentials

BlueDelta conducted a complex credential-harvesting operation targeting critical infrastructure and research institutions in 2025, as revealed by an investigation from Recorded Future’s Insikt Group.

The campaigns leveraged legitimate PDF documents as bait, including publications from the Gulf Research Center titled “Strategic and Political Implications for Israel and Iran: The Day After War” and the EcoClimate Foundation’s report on “Climate Action as a Strategic Priority for the New Pact for the Mediterranean”.

LastPass says hackers stole customer data via Klue, supply chain breach

LastPass has reported a security issue with its vendor, Klue. This incident allowed an attacker unauthorized access to customer data....
Read More
LastPass says hackers stole customer data via Klue, supply chain breach

New Apple Exploit Bypasses Boot Defenses, Possibly Affects Millions of iPhones Worldwide

Researchers at cybersecurity firm Paradigm Shift found a new flaw called usbliter8. This flaw can get around main boot protections...
Read More
New Apple Exploit Bypasses Boot Defenses, Possibly Affects Millions of iPhones Worldwide

India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

A cyber attack seems to have affected one of India's top electronics companies. Tata Electronics has said there was a...
Read More
India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

Anthropic’s Mythos reportedly broke NSA classified systems in hours

The recent finding shows how powerful Mythos is: the AI can access the US government's secret networks in just a...
Read More
Anthropic’s Mythos reportedly broke NSA classified systems in hours

OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

Test before going live is important for AI developers. But there's a problem: testing usually uses fake scenarios that often...
Read More
OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

AryStinger botnet infected thousands of D-Link routers globally

AryStinger has taken control of over 4,000 old D-Link routers to use them as proxies for harmful traffic. The team...
Read More
AryStinger botnet infected thousands of D-Link routers globally

Hacker suspected of sending alerts across Brazil

Brazil's government suspects a hacking attack triggered an unauthorized ‌alert sent to cell phones across parts of the country early...
Read More
Hacker suspected of sending alerts across Brazil

CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

A new open-source cybersecurity tool named CyberSentinel AI v3.0 has come out. It is an important step in self-operated security...
Read More
CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

Barracuda hosts Dhaka roundtable on cyber resilience

Barracuda gathered industry people in Dhaka on 18 June 2026 for a roundtable talk about cyber resilience. The company shared...
Read More
Barracuda hosts Dhaka roundtable on cyber resilience

CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) asked Fortinet users with FortiGate devices on Thursday to act to protect...
Read More
CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

Fraudulent login screens were shown to victims using fake documents to appear legitimate and evade security systems.

Multi-Stage Infrastructure Abuse:

BlueDelta relied on free hosting and tunneling services, showing the group’s ongoing preference for low cost, temporary infrastructure that makes attribution harder.

The campaigns abused Webhook[.]site, InfinityFree, Byet Internet Services, ngrok, and ShortURL to host phishing content, capture credentials, and manage complex redirection chains.

Threat actors used complex redirection methods, starting with shortened URLs that led victims through various webhooks before showing pages to steal credentials.

This method enabled BlueDelta to show real PDF documents for short times, collect beacons with victim email addresses and metadata, and create realistic copies of Microsoft Outlook Web Access, Google, and Sophos VPN login pages.

Analysis of BlueDelta’s credential-harvesting pages revealed iterative improvements in their operational tradecraft.

The group created automated JavaScript functions that automatically captured page URLs, removing the need to manually set exfiltration endpoints.

BlueDelta changed the variable name from “OldPwd” to “password” in recent campaigns, showing improved code for better operations.

On July 16, 2025, BlueDelta made a new phishing page using the free Webhook[.]site API, located at hxxps://webhook[.]site/ff237e88-cbaf-4b0b-b787-6e2f1f2c926f.

Threat actors used unique 32-byte hexadecimal IDs in URL query strings to track individual victims during the credential-harvesting process.

On June 4, 2025, BlueDelta launched a credential-harvesting page disguised as a Sophos VPN password reset page.

Custom scripts monitored victim activity through beacons, sent credentials via HTTP POST in JSON, and redirected victims to real services after submission to avoid raising suspicion.

BlueDelta’s ongoing misuse of legitimate online services highlights the GRU’s view that credential harvesting is an efficient way to gather intelligence for Russian goals.

Organizations can reduce risk by using phishing-resistant multi-factor authentication, blocking unnecessary free hosting and tunneling services, and monitoring authentication attempts from proxy services or unusual ports.

Check Also

AryStinger botnet infected thousands of D-Link routers globally

AryStinger has taken control of over 4,000 old D-Link routers to use them as proxies …