PULSE NAME
FancyBear Exposed: Major OPSEC Blunder Inside Russian Espionage Ops
WHITE Fancy_bear PetrP.73 2026-03-20 Modified: 2026-04-19
39
IOCs
MEDIUM VOLUME
The reported findings on FancyBear, a Russian Advanced Persistent Threat (APT), detail a significant operational security lapse in a campaign known as Operation Roundish. This analysis stemmed from an open directory exposed in January 2026, revealing extensive data including over 2,800 emails and 240 sets of stolen credentials. The exfiltration methods used by FancyBear included creating forwarding rules in victims’ email accounts, enabling silent capture and redirection of emails to attacker-controlled mailboxes.
Indicators of Compromise (39)
All CVE URL domain email hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2023-43770 2026-03-20
URL http://203.161.50.145:8081 2026-03-20
URL http://zhblz.com/zJ2w9x 2026-03-20
URL http://zhblz.com/zJ2w9x/uploadfile/ 2026-03-20
URL http://zhblz.com/zJ2w9x?log= 2026-03-20
URL https://zhblz.com/adbook.js 2026-03-20
URL https://zhblz.com/zJ2w9x 2026-03-20
URL https://zhblz.com/zJ2w9x/uploadfile/` 2026-03-20
URL https://zhblz.com/zJ2w9x?log=t_a_b_f_u_ 2026-03-20
domain afas.ro 2026-03-20
domain arma.gov.ua 2026-03-20
domain army.gr 2026-03-20
domain balkanistudies.bg 2026-03-20
domain bundeswehr.org 2026-03-20
domain dmsu.gov.ua 2026-03-20
domain forces.gc.ca 2026-03-20
domain hellenicnavy.gr 2026-03-20
domain intradef.gouv.fr 2026-03-20
domain krmr.gov.ua 2026-03-20
domain land.gov.ua 2026-03-20
domain mail.bg 2026-03-20
domain mail.gov.ua 2026-03-20
domain mindef.nl 2026-03-20
domain mindigital.gr 2026-03-20
domain nerc.gov.ua 2026-03-20
domain police.gov.ua 2026-03-20
domain probation.gov.ua 2026-03-20
domain roaf.ro 2026-03-20
domain ukroboronprom.com 2026-03-20
domain zhblz.com 2026-03-20
email advenwolf@proton.me 2026-03-20
hostname cd.mil.gr 2026-03-20
hostname docs.google.com.spreadsheets.d.1ip6eeakdebmwteh36vana4hu-glaeksstsht-boujdk.zhblz.com 2026-03-20
hostname gov.vppdr.com 2026-03-20
hostname hndgs.mil.gr 2026-03-20
hostname mail.ascentio.com.ar 2026-03-20
hostname mail.govmk.com 2026-03-20
hostname mod.mil.gr 2026-03-20
hostname navy.mil.gr 2026-03-20