BlueDelta Hackers Target Microsoft OWA, Google, and Sophos VPN for Credential Theft
First seen 8 Jan 2026, 10:52 UTC
•
•93% similarity
•29
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The BlueDelta hacking group, linked to Russian military intelligence, has intensified its credential-stealing efforts throughout 2025. Users of Microsoft Outlook Web Access, Google services, and Sophos VPN have been targeted through multiple phishing campaigns aimed at extracting login information. The attacks occurred between February and September 2025, highlighting a significant escalation in the group's operations.
ThreatCluster AI