Russian BlueDelta hackers ran phishing campaign against Ukrainian webmail users | The Record from Recorded Future News

Russian state-backed hackers, identified as BlueDelta (also known as APT28 or Fancy Bear), conducted a prolonged phishing campaign against users of UKR.NET, a Ukrainian webmail service, from June 2024 to April 2025. The operation aimed to harvest credentials and gather intelligence by luring victims with fake login pages presented through PDF attachments in phishing emails. This campaign is part of BlueDelta’s ongoing cyber-espionage activities targeting entities in support of Russian intelligence objectives.

Edward Kiledjian @ekiledjian