⤷ Title: 29155 compromised!!
════════════════════════
𐀪 Author: Mal Evolence
════════════════════════
ⴵ Time: Wed, 19 Feb 2025 12:24:42 GMT
════════════════════════
⌗ Tags: #whispergate #hacking #russian_intelligence #cadet_blizzard #gru_29155
════════════════════════
𐀪 Author: Mal Evolence
════════════════════════
ⴵ Time: Wed, 19 Feb 2025 12:24:42 GMT
════════════════════════
⌗ Tags: #whispergate #hacking #russian_intelligence #cadet_blizzard #gru_29155
Medium
29155 compromised!!
TL;DR I have 3 years of logs from a probably Cadet Blizzard server named Egeon, essentially showing their targets, exposing 29155 sabotage…
⤷ Title: GRU Unit 29155 Uses SocGholish to Target US Firm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 02:14:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Arctic Wolf Labs #cyber_espionage #GRU Unit 29155 #Malware_as_a_Service #Mythic Agent #RomCom #russia #SocGholish #TA569 #Ukraine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 26 Nov 2025 02:14:54 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #Arctic Wolf Labs #cyber_espionage #GRU Unit 29155 #Malware_as_a_Service #Mythic Agent #RomCom #russia #SocGholish #TA569 #Ukraine
Daily CyberSecurity
GRU Unit 29155 Uses SocGholish to Target US Firm
Arctic Wolf Labs reveals Russian GRU Unit 29155 using SocGholish to deploy RomCom malware against a US firm with ties to Ukraine.
⤷ Title: Amazon: Russian GRU hackers favor misconfigured devices over vulnerabilities
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 17:55:38 +0000
════════════════════════
⌗ Tags: #Security #0day #Amazon #APT44 #AWS #Curly COMrades #Cyber Attack #Cyber Crime #Cybersecurity #GRU #Malware #Russia #Sandworm #Seashell Blizzard #Vulnerability
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 17:55:38 +0000
════════════════════════
⌗ Tags: #Security #0day #Amazon #APT44 #AWS #Curly COMrades #Cyber Attack #Cyber Crime #Cybersecurity #GRU #Malware #Russia #Sandworm #Seashell Blizzard #Vulnerability
Hackread
Amazon: Russian GRU hackers favor misconfigured devices over vulnerabilities
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Sandworm’s Tactical Pivot: Russian GRU Abandons Zero-Days to Weaponize Misconfigured Edge Devices
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 01:57:59 +0000
════════════════════════
⌗ Tags: #Cyber Security #Amazon Threat Intelligence #APT44 #Credential Replay #Critical Infrastructure #Curly COMrades #Edge Device #GRU #misconfiguration #SANDWORM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 01:57:59 +0000
════════════════════════
⌗ Tags: #Cyber Security #Amazon Threat Intelligence #APT44 #Credential Replay #Critical Infrastructure #Curly COMrades #Edge Device #GRU #misconfiguration #SANDWORM
Daily CyberSecurity
Sandworm’s Tactical Pivot: Russian GRU Abandons Zero-Days to Weaponize Misconfigured Edge Devices
Sandworm (APT44) has shifted tactics, favoring misconfigured edge devices over complex exploits to breach energy and telecom sectors via credential replay.
⤷ Title: The GRU’s Silent Shift: How BlueDelta Hijacks Ukrainian Webmail Using ngrok and Mocky
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:06:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #2FA bypass #APT28 #BlueDelta #Credential Theft #cyber_espionage #Fancy Bear #GRU #Ngrok #phishing #UKR.NET #Ukraine
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Dec 2025 00:06:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #2FA bypass #APT28 #BlueDelta #Credential Theft #cyber_espionage #Fancy Bear #GRU #Ngrok #phishing #UKR.NET #Ukraine
Daily CyberSecurity
The GRU’s Silent Shift: How BlueDelta Hijacks Ukrainian Webmail Using ngrok and Mocky
BlueDelta (APT28) is targeting UKR.NET users with a sophisticated phishing campaign using ngrok and Mocky to bypass security and steal 2FA codes.
⤷ Title: BlueDelta Espionage: Russian Hackers Abuse Free Apps to Target Energy Sector
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 00:08:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #BlueDelta #Credential Harvesting #cyber_espionage #Energy Sector Security #GRU #phishing #Recorded Future #threat intelligence #Webhook.site
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 09 Jan 2026 00:08:34 +0000
════════════════════════
⌗ Tags: #Cyber Security #BlueDelta #Credential Harvesting #cyber_espionage #Energy Sector Security #GRU #phishing #Recorded Future #threat intelligence #Webhook.site
Daily CyberSecurity
BlueDelta Espionage: Russian Hackers Abuse Free Apps to Target Energy Sector
A notorious Russian state-sponsored hacking group has evolved its digital espionage toolkit, launching a sophisticated wave of credential-harvesting attacks targeting energy researchers and govern…
⤷ Title: APT28 Hijacks Home Routers to Steal Corporate Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:20:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #APT28 #CVE_2023_50224 #cybersecurity #DNS hijacking #Fancy Bear #GRU #MikroTik #NCSC #OAuth Theft #router security #TP_Link
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:20:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AiTM #APT28 #CVE_2023_50224 #cybersecurity #DNS hijacking #Fancy Bear #GRU #MikroTik #NCSC #OAuth Theft #router security #TP_Link
Daily CyberSecurity
APT28 Hijacks Home Routers to Steal Corporate Credentials
NCSC unmasks APT28’s "digital funnel" using router DNS hijacking to steal OAuth tokens and passwords. Protect your remote workforce—patch your routers now.