Summary
Key Points:
- APT28 (BlueDelta) is conducting a credential-harvesting campaign targeting individuals in the Turkish energy sector and European policy organizations, utilizing tailored phishing tactics.
- The attacks impact users associated with specific organizations in Turkey, North Macedonia, and Uzbekistan, leveraging fake login pages that mimic legitimate services to capture credentials without raising suspicion.
- Recommended actions include implementing robust email filtering, user training on recognizing phishing attempts, and monitoring for unusual login activity from affected regions.
Technical Details: The campaign employs fake login pages styled after Microsoft OWA and Google services, redirecting users to legitimate sites post-credential entry. The attackers utilize services like Webhook.site to host phishing pages and exfiltrate stolen data.
MITRE ATT&CK Techniques:
- T1566.001 - Phishing: Spearphishing Link (Initial Access)
- T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
- T1003.001 - OS Credential Dumping: Credentials from Web Browsers (Credential Access)
IOCs Mentioned:
- webhook[.]site
- InfinityFree
- Byet Internet Services
- ngrok
Join the discussion — sign up to comment, upvote, and save articles.