Join our Newsletter — 33% off our NHI Course

Russian APT phishes the Baltics and Balkans: what should teams do?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: A Russian APT has run a credential phishing campaign since at least 2023, using HTML attachments, blurred decoy pages and password checks before exfiltrating credentials to formcarry.com, according to Strike Ready. The pattern shows how phishing lures can adapt to local targets and still bypass weak identity controls because capture, validation and forwarding all sit outside normal user awareness.

Editorial analysis by NHI Mgmt Group, based on content published by Strike Ready: “Russian APT actor phishes the Baltics and the Balkans”.

Key questions

Q: What breaks when users can enter credentials into a phishing page that looks like a legitimate document?

A: The control that breaks is the assumption that a user will recognise the credential surface before typing.

Q: Why do password-only defences fail against credential phishing campaigns like this?

A: Password-only defences fail because a stolen secret is still a valid secret until something else proves otherwise.

Q: How can security teams tell whether a phishing page is built to steal credentials or just to deceive users?

A: Look at what happens after input.

Practitioner guidance

  • Harden credential capture controls at the browser edge Block or warn on HTML email attachments that render interactive login forms, especially when they impersonate local government or internal notices.
  • Inspect phishing relay destinations and form handlers Track outbound submissions to third-party form services and similar collection endpoints, not just the visible lure domain.
  • Reduce the value of harvested passwords Push MFA, conditional access and passwordless options so a stolen password alone is less useful after capture.

Bottom line: This campaign demonstrates that phishing remains a live credential-capture problem, with HTML attachments and decoy pages used to harvest usable secrets.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Credential phishing has become a credential-lifecycle problem, not an email problem. This campaign succeeds because the attack surface begins at the point of input, not the point of inbox delivery. Once a user types a secret into a hostile page, downstream authentication controls are already playing catch-up. Identity teams should read this as a governance failure in credential handling, not just a messaging failure in awareness.

A question worth separating out:

Q: Should organisations prioritise passwordless access over phishing awareness for this threat pattern?

A: Yes, where the environment supports it. Awareness still matters, but passwordless and stronger second factors reduce the payoff of a successful capture. The decision is especially important for high-risk users and accounts that are regularly targeted by themed or language-specific phishing lures.

👉 Read our full editorial: Russian APT phishing campaign exposes credential theft blind spots



   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.