← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
FancyBear Exposed: Major OPSEC Blunder Inside Russian Espionage Ops
The reported findings on FancyBear, a Russian Advanced Persistent Threat (APT), detail a significant operational security lapse in a campaign known as Operation Roundish. This analysis stemmed from an open directory exposed in January 2026, revealing extensive data including over 2,800 emails and 240 sets of stolen credentials. The exfiltration methods used by FancyBear included creating forwarding rules in victims’ email accounts, enabling silent capture and redirection of emails to attacker-controlled mailboxes.
MITRE ATT&CK & Malware Families
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| CVE | CVE-2023-43770 | — | 2026-03-20 | |
| URL | http://203.161.50.145:8081 | — | 2026-03-20 | |
| URL | http://zhblz.com/zJ2w9x | — | 2026-03-20 | |
| URL | http://zhblz.com/zJ2w9x/uploadfile/ | — | 2026-03-20 | |
| URL | http://zhblz.com/zJ2w9x?log= | — | 2026-03-20 | |
| URL | https://zhblz.com/adbook.js | — | 2026-03-20 | |
| URL | https://zhblz.com/zJ2w9x | — | 2026-03-20 | |
| URL | https://zhblz.com/zJ2w9x/uploadfile/` | — | 2026-03-20 | |
| URL | https://zhblz.com/zJ2w9x?log=t_a_b_f_u_ | — | 2026-03-20 | |
| domain | afas.ro | — | 2026-03-20 | |
| domain | arma.gov.ua | — | 2026-03-20 | |
| domain | army.gr | — | 2026-03-20 | |
| domain | balkanistudies.bg | — | 2026-03-20 | |
| domain | bundeswehr.org | — | 2026-03-20 | |
| domain | dmsu.gov.ua | — | 2026-03-20 | |
| domain | forces.gc.ca | — | 2026-03-20 | |
| domain | hellenicnavy.gr | — | 2026-03-20 | |
| domain | intradef.gouv.fr | — | 2026-03-20 | |
| domain | krmr.gov.ua | — | 2026-03-20 | |
| domain | land.gov.ua | — | 2026-03-20 | |
| domain | mail.bg | — | 2026-03-20 | |
| domain | mail.gov.ua | — | 2026-03-20 | |
| domain | mindef.nl | — | 2026-03-20 | |
| domain | mindigital.gr | — | 2026-03-20 | |
| domain | nerc.gov.ua | — | 2026-03-20 | |
| domain | police.gov.ua | — | 2026-03-20 | |
| domain | probation.gov.ua | — | 2026-03-20 | |
| domain | roaf.ro | — | 2026-03-20 | |
| domain | ukroboronprom.com | — | 2026-03-20 | |
| domain | zhblz.com | — | 2026-03-20 | |
| advenwolf@proton.me | — | 2026-03-20 | ||
| hostname | cd.mil.gr | — | 2026-03-20 | |
| hostname | docs.google.com.spreadsheets.d.1ip6eeakdebmwteh36vana4hu-glaeksstsht-boujdk.zhblz.com | — | 2026-03-20 | |
| hostname | gov.vppdr.com | — | 2026-03-20 | |
| hostname | hndgs.mil.gr | — | 2026-03-20 | |
| hostname | mail.ascentio.com.ar | — | 2026-03-20 | |
| hostname | mail.govmk.com | — | 2026-03-20 | |
| hostname | mod.mil.gr | — | 2026-03-20 | |
| hostname | navy.mil.gr | — | 2026-03-20 |
References (1)