#FancyBear
Russian-linked Fancy Bear exploits Microsoft RTF zero-day (CVE-2026-21509) to deploy malware in Eastern Europe. Targets include Ukraine, Slovakia, and Romania. #CyberSecurity #APT28 #ZeroDay #FancyBear Link: thedailytechfeed.com/fancy-bear-e...
February 11, 2026 at 6:43 PM
#APT28 Weaponizes MS Office Flaw to #Spy on #NATO & #Military

#Russia state-sponsored group #FancyBear has launched a sophisticated espionage campaign, striking #Europe #military & #government through a major security vulnerability in #Microsoft #Office.

securityonline.info/apt28-weapon...
APT28 Weaponizes Office Flaw to Spy on NATO & Military
APT28 (Fancy Bear) weaponized CVE-2026-21509 in 24 hours to target NATO. New "BeardShell" and "NotDoor" malware steals emails. Patch Office now.
securityonline.info
February 9, 2026 at 9:00 AM
APT28, noto come Fancy Bear, lancia attacco di credential harvesting in Europa e Asia

📌 Link all'articolo : www.redhotcyber.com/post/apt...

#redhotcyber #news #cybersecurity #hacking #malware #ransomware #apt28 #fancybear #credentialharvesting
January 13, 2026 at 7:00 AM
Russian BlueDelta (Fancy Bear) uses PDFs to steal logins in just 2 seconds, targeting energy and research professionals globally.

Read: hackread.com/russian-blue...

#BlueDelta #FancyBear #Phishing #CyberSecurity #Russia
Russian BlueDelta (Fancy Bear) Uses PDFs to Steal Logins in Just 2 Seconds
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
January 12, 2026 at 11:07 PM
Today, we released new @RecordedFuture research detailing BlueDelta’s expanded credential-harvesting activity observed between February and September 2025. #BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #ITG05 #PawnStorm #Sednit #Sofacy #TA422 (1/5) www.recordedfuture.com/research/gru...
GRU-Linked BlueDelta Evolves Credential Harvesting
Insikt Group reveals how GRU-linked BlueDelta evolved credential-harvesting campaigns targeting government, energy, and research organizations across Europe and Eurasia.
www.recordedfuture.com
January 7, 2026 at 3:39 PM
Today, we released new @RecordedFuture research detailing BlueDelta’s sustained credential-harvesting campaign targeting UKR.NET users between June 2024 and April 2025. www.recordedfuture.com/research/blu...
#BlueDelta #APT28 #FANCYBEAR #ForestBlizzard #FROZENLAKE #PawnStorm #Sednit #Sofacy (1/5)
BlueDelta’s Persistent Campaign Against UKR.NET
Discover how Russia’s BlueDelta targets UKR.NET users with advanced credential-harvesting campaigns, evolving tradecraft, and multi-stage phishing techniques.
www.recordedfuture.com
December 17, 2025 at 3:46 PM
“World-class” Russian Fancy Bear hacker wanted by FBI and arrested in Thailand is likely GRU officer Aleksey Lukashev

theins.ru/en/news/286815

#FancyBear #hacker
“World-class” Russian hacker wanted by FBI and arrested in Thailand is likely GRU officer Aleksey Lukashev
On Nov. 12, Thai cyber police announced the arrest of a 35-year-old Russian citizen on the island of Phuket, adding that the unnamed suspect stands wanted in the United States on charges of hacking go...
theins.ru
November 13, 2025 at 9:40 PM
Ni sous le format cyber-attaque? NoName057, FancyBear, etc c'est juste des preuves d'amour tumul tueuses?
October 23, 2025 at 8:01 PM
One word: FancyBear
October 21, 2025 at 8:53 PM
Dus, Putin heeft weer even uitgelegd hoe Trump ook alweer aan zijn presidentschap kwam? #CozyBear #FancyBear
Die man zit heel diep in de zakken van Putin...
October 20, 2025 at 9:21 AM
Gruppi come Sandworm, Fancy Bear e Cozy Bear guidano nuove minacce cyber contro infrastrutture ucraine con attacchi avanzati di phishing e malware.

#apt #Armagedon #CERTUA #evidenza #FancyBear #Gamaredon #Russia #sandworm
www.matricedigitale.it/2025/10/09/c...
October 9, 2025 at 10:39 AM
Great work by Sekoia uncovering new #BlueDelta #APT28 #Sofacy #FancyBear #ForestBlizzard #TAG110 malware samples. Linked to CERT-UA’s BeardShell & Covenant frameworks + revealed fresh weaponized docs & subtle TTPs. Activity ties to Russia-nexus ops incl. Double-Tap. blog.sekoia.io/apt28-operat...
APT28 Operation Phantom Net Voxel
APT28 Operation Phantom Net Voxel: weaponized Office lures, COM-hijack DLL, PNG stego to Covenant Grunt via Koofr, BeardShell on icedrive.
blog.sekoia.io
September 16, 2025 at 9:24 AM
Schoot me ineens te binnen:
#Schoof is niet mee naar de ontmoeting tussen #Zelensky en #Trump. Maar hij weet exact hoe het gegaan is met #CozyBear and #FancyBear bij de eerste termijn van Trump. De #hacks op stemvoorzieningen en de #Bots fabrieken.
En heeft toendertijd #Rutte geïnformeerd...
August 18, 2025 at 6:53 AM
July 28, 2025 at 2:47 PM
Cato CTRL™ Threat Research: Analyzing LAMEHUG | Cato Networks

https://www.catonetworks.com/blog/cato-ctrl-threat-research-analyzing-lamehug/
www.catonetworks.com
July 23, 2025 at 1:30 PM
Hmm. Did she not read about #CozyBear and #FancyBear ??

www.dni.gov/index.php/ne...
July 23, 2025 at 2:45 AM
UK uncovers novel #Microsoft snooping #malware, blames and sanctions GRU cyberspies
www.theregister.com/2025/07/20/u...

UK govt warns that Russia's #APT28 (aka #FancyBear or #ForestBlizzard) harvesting email credentials & stealing access to accounts.
#CyberSecurity #InfoSec #CyberCrime
UK uncovers novel Microsoft snooping malware, blames GRU
: Fancy Bear can't keep its claws out of Outlook inboxes
www.theregister.com
July 21, 2025 at 3:06 PM
The NCSC has revealed that the Fancy Bear hacking group, linked to Russian military intelligence, is behind the use of sophisticated malware that steals victims’ login details and tokens to allow attackers long-term access to email accounts.

www.digit.fyi/ncsc-warns-f... #malware #GRU #FancyBear
NCSC Warns Fancy Bear Malware Hijacking Email Accounts
The NCSC has found the Fancy Bear hacking group, linked to Russian intelligence, behind the use of malware that steals victims’ email logins.
www.digit.fyi
July 21, 2025 at 10:30 AM
UK strikes back at Russian #cyber aggression. New GRU-linked #malware targeting #Microsoft email systems uncovered. Attribution points to #APT28 with sanctions now in place.
#CyberSecurity #Infosec #NationalSecurity #FancyBear
UK uncovers novel Microsoft snooping malware, blames GRU
: Fancy Bear can't keep its claws out of Outlook inboxes
www.theregister.com
July 21, 2025 at 7:30 AM
The U.K.’s assistance on Sanctions Package 18, particularly the cyber-focused measures targeting APT28 (GRU26165), was especially valuable.

I look forward to leading the narrative through Sanctions Package 19, which will address APT29 (SVR/FancyBear)
July 19, 2025 at 9:10 AM
Groupe de hackers russes APT28 (Fancy Bear) identifié comme lié au GRU. Nouvelles révélations sur leurs activités et tactiques. Impact potentiel sur la sécurité internationale. APT28 #FancyBear #GRU #Cyberattaque #Russie #Cybersecurité #Intelligence Link
July 13, 2025 at 7:07 PM