GRU FancyBear C2 Server Exposed for 500+ Days After Major OPSEC Failure
APT28's 500-day retention of a CERT-UA-attributed C2 most plausibly reflects operators' judgment that Roundcube exploitation against priority government mail servers outweighed exposure risk, per a single Ctrl-Alt-Intel open-directory analysis. The 240 credential sets with TOTP secrets and 140 silent Sieve rules confirm an autonomous exfiltration pipeline, making identified victims across Ukraine's prosecutors, Romania's Air Force, and NATO-member defense ministries a floor on the breach, not a ceiling. Organizations in this set are likely to face renewed spear-phishing or re-exploitation within the next 90 days, given GRU units' pattern of reconstituting against priority targets following infrastructure setbacks. The artifacts' completeness fits deliberate provocation as readily as negligence; GRU services have precedent for seeding accessible infrastructure to shape Western attribution.
1 sources
- FancyBear Exposed: Major OPSEC Blunder Inside Russian Espionage Ops -
Ctrl-Alt-Intel