216.73.216.6

Russian APT actor phishes the Baltics and the Balkans

· Published 16/12/2025 09:50 · Modified 21/12/2025 19:31

Export JSON

Essential information

Published
16/12/2025 09:50
Modified
21/12/2025 19:31
Tags
2025-12-16 apt credential-theft eastern europe government phishing
Related entities
1 intrusion sets (apt), 7 techniques (mitre), 10 others

Description

A Russian Advanced Persistent Threat () group has been targeting entities in the Baltic and Balkan regions with sophisticated campaigns. The attackers use email attachments spoofing official documents to lure victims into entering their credentials on fake login pages. The pages employ blurred background images and complex password validation mechanisms. Stolen credentials are sent to a third-party service, even if they don't meet the specified complexity requirements. This campaign has been active since at least 2023, with various lures tailored to specific targets in countries such as Moldova, Ukraine, Lithuania, Bosnia and Herzegovina, Macedonia, Montenegro, Spain, and Bulgaria.

External references