TL;DR: A Russian APT has run a credential phishing campaign since at least 2023, using HTML attachments, blurred decoy pages and password checks before exfiltrating credentials to formcarry.com, according to Strike Ready. The pattern shows how phishing lures can adapt to local targets and still bypass weak identity controls because capture, validation and forwarding all sit outside normal user awareness.
At a glance
What this is: This is an analysis of a Russian APT credential phishing campaign that used HTML attachments and tailored decoys to harvest passwords and forward them to an external service.
Why it matters: It matters because identity teams need to treat phishing as a credential-lifecycle problem, not just a user-awareness problem, especially when lures are localised and data is still accepted after failed validation.
Context
A credential phishing campaign turns identity compromise into a delivery problem: the lure only needs one successful capture path to create downstream access risk. In this case, the phish used HTML attachments, translated political lures and a password-checking page to make the interaction look legitimate before sending captured data onward.
For identity programmes, the security gap is not just the email filter. The real failure is that a phishing flow can still harvest usable credentials even when the user is not convinced by the first page, which means account protection has to assume hostile capture outside the normal sign-in sequence.
Key questions
A: The control that breaks is the assumption that a user will recognise the credential surface before typing. Once a phishing page accepts input, the attacker owns the capture moment. Email filtering and awareness training help, but they do not stop exfiltration if the page is already live and convincing.
Q: Why do password-only defences fail against credential phishing campaigns like this?
A: Password-only defences fail because a stolen secret is still a valid secret until something else proves otherwise. Attackers can reuse it immediately, test it across services or combine it with MFA fatigue and session hijacking. The risk is not just disclosure, but the downstream access that follows.
A: Look at what happens after input. If a page validates passwords, posts data to a relay service, or accepts credentials even when the entry is malformed, it is operating as theft infrastructure. The presence of business logic often signals an attacker trying to improve capture quality, not safety.
Q: Should organisations prioritise passwordless access over phishing awareness for this threat pattern?
A: Yes, where the environment supports it. Awareness still matters, but passwordless and stronger second factors reduce the payoff of a successful capture. The decision is especially important for high-risk users and accounts that are regularly targeted by themed or language-specific phishing lures.
Technical breakdown
HTML attachment phishing as a credential capture channel
HTML attachments let attackers host an interactive credential form locally in the message rather than linking to a separate site. That reduces obvious indicators such as suspicious domains in the body of the email and can make the lure feel more like a document viewer than a login page. In this campaign, the attachment rendered a decoy page and then collected input through scripted form handling. The important point is that the browser becomes the authentication surface, even though no legitimate identity provider is involved.
Practical implication: treat HTML attachments as active phishing infrastructure, not just harmless documents.
Password validation does not stop credential theft
The phish checked the entered password against a regex before forwarding it, but the data was still stolen even when the password failed the check. That means validation logic can exist for attacker convenience, not user protection. It may be used to filter inputs, test password quality, or capture secondary credentials that the attacker expects to reuse elsewhere. For defenders, the presence of a password rule in the page is not evidence of safety. It is often evidence of a more tailored theft workflow.
Practical implication: assume any entered secret is lost once a phishing form loads, regardless of on-page validation.
External forwarding creates the exfiltration path
Captured credentials were POSTed to formcarry.com, which shows a common phishing pattern: the fake login page acts as a collection layer while a third-party form or relay service becomes the actual transport layer. That separation can frustrate blocklists that look only for the visible lure domain. It also complicates incident response because the credential sink may sit on a benign-looking service rather than the page the user saw. The control problem is therefore not just detection, but the whole trust chain behind the collection endpoint.
Practical implication: monitor outbound form-handling and relay destinations, not only the visible phishing domain.
NHI Mgmt Group analysis
Credential phishing has become a credential-lifecycle problem, not an email problem. This campaign succeeds because the attack surface begins at the point of input, not the point of inbox delivery. Once a user types a secret into a hostile page, downstream authentication controls are already playing catch-up. Identity teams should read this as a governance failure in credential handling, not just a messaging failure in awareness.
Phishing pages now behave like lightweight identity brokers. The script in this campaign did not need sophisticated infrastructure to be effective. It only needed a believable document flow, a validation step and an exfiltration endpoint. That combination shows how attackers can separate user deception from transport mechanics, which makes simplistic URL-based controls increasingly incomplete.
Localisation and lure targeting are now part of credential assurance. The campaign embedded target-specific government themes, which increases the likelihood that users will interact with the page. This is not merely social engineering content quality. It is an access-control issue because tailored lures raise the probability that a usable credential reaches an attacker-controlled relay. The implication is that identity programmes need stronger assumptions about secret capture under context-specific persuasion.
Secret reuse remains the structural weakness that phishing exploits. The page’s willingness to steal input even after a failed regex check suggests the attacker values any credential artefact, not just one perfect password. That is consistent with a wider ecosystem where one captured secret can unlock additional accounts or services. Practitioners should treat every harvested credential as a possible entry point into a broader identity chain.
Form relay abuse is the named concept here: hostile input plus benign transport. The attacker’s use of an external form-handling service shows how collection and delivery can be split across ordinary-looking infrastructure. That matters because defenders often key off the visible lure, while the actual theft path depends on the relay. The operational conclusion is that trust must extend to the entire collection pipeline, not just the page the victim sees.
What this signals
Credential capture needs to be treated as an identity control failure. The campaign shows that once a password is entered into an attacker-controlled page, the question is no longer whether the inbox was protected well enough. The question is whether the organisation has reduced the usefulness of the captured secret through stronger authentication and tighter session controls.
Localised lures make phishing governance harder, not easier. When attackers mirror regional government language and document themes, they raise the odds that a user will engage with the page long enough to submit a secret. Security teams should expect these campaigns to behave more like targeted identity operations than generic spam.
Hostile form relays widen the detection gap. A page that forwards data to a benign-looking form service can evade controls tuned only to suspicious domains. That pushes defenders toward broader telemetry on web form behaviour, identity sign-in anomalies and credential replay attempts.
For practitioners
- Harden credential capture controls at the browser edge Block or warn on HTML email attachments that render interactive login forms, especially when they impersonate local government or internal notices.
- Inspect phishing relay destinations and form handlers Track outbound submissions to third-party form services and similar collection endpoints, not just the visible lure domain.
- Reduce the value of harvested passwords Push MFA, conditional access and passwordless options so a stolen password alone is less useful after capture.
- Tune detection for lure localisation Watch for politically themed or region-specific attachments that mimic official notices, because tailored content materially raises click and entry rates.
Key takeaways
- This campaign demonstrates that phishing remains a live credential-capture problem, with HTML attachments and decoy pages used to harvest usable secrets.
- The attacker accepted credentials even after a regex check failed, which shows that validation logic on a phishing page does not protect the victim.
- Stronger authentication, reduced password dependence and better monitoring of relay services are the controls most likely to limit the damage.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The campaign steals credentials through a fake login surface, making authentication the direct attack target. |
| NHI-10 — Human Use of NHI | The lure abuses human-entered secrets that later serve non-human or automated access paths. | |
| Recommendation — Harden authentication flows so captured credentials cannot be reused as a standalone path to access. Separate human-entered credentials from machine access paths and remove shared secret reuse. | ||
| MITRE ATT&CK | TA0006 — Credential Access | Credential collection is the central adversary activity in this phishing campaign. |
| Recommendation — Map phishing detections to credential access techniques and prioritise controls that block secret harvesting. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | The article’s core problem is stolen passwords and the lifecycle weakness that follows. |
| Recommendation — Apply authenticator management controls to reduce the value and lifespan of captured credentials. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Reused credentials only matter when access permissions remain too broad after compromise. |
| Recommendation — Review access permissions so a single stolen credential cannot open unnecessary downstream systems. | ||
Key terms
- Credential Phishing: Credential phishing is a social engineering attack that tricks a person into handing over login secrets such as passwords or passcodes. In identity programmes, it matters because the stolen secret can be reused to impersonate the user, access applications, and bypass ordinary authentication controls.
- Relay Endpoint: A relay endpoint is the service or infrastructure that receives stolen data from a phishing page and forwards it elsewhere. It may look benign on the surface, but it is part of the theft chain because it moves captured credentials out of the victim-controlled environment.
- Lure Localisation: Lure localisation is the tailoring of phishing content to a specific language, organisation, region or political context to increase trust and engagement. The technique is a force multiplier for credential theft because it makes the fake interaction feel operationally relevant to the target.
- Password Replay Risk: Password replay risk is the possibility that a stolen password will be reused across another system, service or session before the victim can respond. The risk is highest when authentication is password-centric and weakly bound to device, context or additional verification.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org