Adversary Intelligence — 2026-05-07

GRU FancyBear C2 Server Exposed for 500+ Days After Major OPSEC Failure

Hunt.io on March 11 published findings on an APT28/FancyBear open-directory at US-based NameCheap VPS 203.161.50.145, first archived January 13; Ctrl-Alt-Intel then identified a second open-directory on the same host containing C2 source code, JavaScript payloads, and campaign telemetry. Ctrl-Alt-Intel reports recovery of more than 11,000 exfiltrated government and military emails, 240 credential sets including TOTP 2FA secrets, 140 silent Sieve forwarding rules, and 11,500 harvested contact addresses. Confirmed victims span Ukraine's regional prosecutors' offices, Romania's Air Force, Greece's National Defence General Staff, Serbia's Ministry of Defence, and Bulgarian government entities. Ctrl-Alt-Intel reports the group operated from the same C2 server for over 500 days after CERT-UA first attributed the IP in September 2024.

Analysis
APT28's 500-day retention of a CERT-UA-attributed C2 most plausibly reflects operators' judgment that Roundcube exploitation against priority government mail servers outweighed exposure risk, per a single Ctrl-Alt-Intel open-directory analysis. The 240 credential sets with TOTP secrets and 140 silent Sieve rules confirm an autonomous exfiltration pipeline, making identified victims across Ukraine's prosecutors, Romania's Air Force, and NATO-member defense ministries a floor on the breach, not a ceiling. Organizations in this set are likely to face renewed spear-phishing or re-exploitation within the next 90 days, given GRU units' pattern of reconstituting against priority targets following infrastructure setbacks. The artifacts' completeness fits deliberate provocation as readily as negligence; GRU services have precedent for seeding accessible infrastructure to shape Western attribution.
1 sources
  1. FancyBear Exposed: Major OPSEC Blunder Inside Russian Espionage Ops - Ctrl-Alt-Intel

View in full brief →

UNCLASSIFIED // OPEN SOURCE