Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

UK Sanctions Russian APT 28 Hackers for Attacking Microsoft Cloud Service Login Details

Posted on July 22, 2025July 22, 2025 By CWS

The UK Authorities has imposed sanctions on Russian navy intelligence models and 18 people following the publicity of a classy cyber espionage marketing campaign focusing on Microsoft cloud providers. 

The Nationwide Cyber Safety Centre (NCSC) revealed that the Russian Superior Persistent Risk group APT 28 deployed beforehand unknown malware known as AUTHENTIC ANTICS to steal login credentials and keep persistent entry to sufferer e-mail accounts.

Key Takeaways1. UK sanctions Russian GRU models and 18 people for Microsoft cloud cyber assaults.2. AUTHENTIC ANTICS malware steals login credentials by way of faux login home windows.3. UK boosts protection spending to 2.6% GDP to counter Russian threats.

AUTHENTIC ANTICS Targets Microsoft Cloud Surroundings

The AUTHENTIC ANTICS malware represents a big evolution in Russian cyber capabilities, particularly designed to focus on Microsoft cloud environments by way of refined credential harvesting methods. 

In response to the NCSC’s technical evaluation, the malware operates by periodically displaying legitimate-looking login home windows that immediate customers to enter their credentials. 

As soon as captured, these credentials are intercepted alongside OAuth authentication tokens, which give the attackers with prolonged entry to Microsoft providers with out triggering conventional safety alerts.

The malware’s stealth capabilities prolong past easy credential theft. AUTHENTIC ANTICS can exfiltrate delicate knowledge by robotically sending emails from compromised accounts to actor-controlled addresses whereas making certain these messages by no means seem within the sufferer’s despatched folder. 

This method permits for covert knowledge extraction that may stay undetected for prolonged intervals, enabling long-term intelligence gathering operations.

The UK’s response consists of complete sanctions towards three GRU models: 26165, 29155, and 74455, together with 18 GRU officers and brokers concerned in world cyber and data interference operations. 

Overseas Secretary David Lammy emphasised that these measures reveal the UK’s dedication to countering Russian hybrid threats, stating that “GRU spies are working a marketing campaign to destabilise Europe, undermine Ukraine’s sovereignty and threaten the security of British residents”.

This attribution aligns with the Strategic Defence Assessment’s identification of Russia as essentially the most acute risk going through the UK. 

The federal government has introduced the biggest sustained enhance in defence spending for the reason that Chilly Battle, growing to 2.6% of GDP by 2027 as a part of efforts to counter cyber and hybrid threats.

The NCSC’s investigation confirms that APT 28, additionally recognized in open supply communities as Fancy Bear, Forest Blizzard, and Blue Delta, operates as a part of Russia’s GRU eighty fifth Primary Particular Service Centre, Army Unit 26165. 

Paul Chichester, NCSC Director of Operations, famous that “the usage of AUTHENTIC ANTICS malware demonstrates the persistence and class of the cyber risk posed by Russia’s GRU”.

The malware discovery emerged from a cyber incident investigated by Microsoft and NCC Group in 2023, highlighting the significance of public-private cybersecurity partnerships. 

The UK’s technical attribution has been coordinated with worldwide companions, reinforcing collective protection towards Russian cyber operations focusing on vital infrastructure and democratic establishments throughout Europe and past.

Increase detection, cut back alert fatigue, speed up response; all with an interactive sandbox constructed for safety groups -> Strive ANY.RUN Now 

Cyber Security News Tags:APT, Attacking, Cloud, Details, Hackers, Login, Microsoft, Russian, Sanctions, Service

Post navigation

Previous Post: How to Advance from SOC Manager to CISO?
Next Post: Dior Says Personal Information Stolen in Cyberattack

Related Posts

SpyCloud Unveils Top 10 Cybersecurity Predictions Poised to Disrupt Identity Security in 2026 Cyber Security News
CISA Warns of Citrix RCE and Privilege Escalation Vulnerabilities Exploited in Attacks Cyber Security News
CISA Adds Fortinet Vulnerability to KEV Catalog After Active Exploitation Cyber Security News
Hackers Allegedly Selling WinRAR 0-day Exploit on Dark Web Forums for $80,000 Cyber Security News
CISA Adds ASUS Embedded Malicious Code Vulnerability to KEV List Following Active Exploitation Cyber Security News
CyberVolk Ransomware Attacking Windows System in Critical Infrastructure and Scientific Institutions Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Leveraging OSINT Tools for Enhanced Cybersecurity Threat Intelligence
  • Data Breach at Texas Gas Station Operator Exposes Info of 377,000+ Customers
  • MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
  • Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime
  • New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Leveraging OSINT Tools for Enhanced Cybersecurity Threat Intelligence
  • Data Breach at Texas Gas Station Operator Exposes Info of 377,000+ Customers
  • MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
  • Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime
  • New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark