

{"id":567,"date":"2025-07-22T08:45:20","date_gmt":"2025-07-22T03:15:20","guid":{"rendered":"https:\/\/www.securis360.com\/blog\/?p=567"},"modified":"2026-02-18T06:30:41","modified_gmt":"2026-02-18T06:30:41","slug":"russia-linked-to-new-malware-targeting-email-accounts-for-espionage","status":"publish","type":"post","link":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/","title":{"rendered":"Russia Linked to New Malware Targeting Email Accounts for Espionage"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The cyber threat landscape continues to evolve, with state-sponsored actors employing increasingly stealthy and sophisticated tactics. In a recent advisory, the UK\u2019s National Cyber Security Centre (NCSC) revealed the discovery of a <strong>new malware strain named &#8220;Authentic Antics&#8221;<\/strong>, attributed to the notorious Russian threat group <strong>APT28<\/strong>, also known as <strong>Fancy Bear<\/strong> and linked to Russia\u2019s GRU (military intelligence).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Designed to infiltrate and persist within <strong>Microsoft cloud environments<\/strong>, Authentic Antics demonstrates how advanced cyber espionage operations have become\u2014and underscores the persistent and growing threat posed by <strong>nation-state actors<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Who is APT28?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">APT28, also known as <strong>Fancy Bear<\/strong>, <strong>Sofacy<\/strong>, or <strong>Pawn Storm<\/strong>, is a long-known <strong>advanced persistent threat (APT)<\/strong> group believed to be affiliated with <strong>Russia\u2019s GRU military intelligence agency<\/strong>. The group has been linked to high-profile cyber operations against governments, defense contractors, and technology firms around the world.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">APT28 has consistently used phishing, malware, and credential theft to achieve its goals. But with the introduction of Authentic Antics, the threat landscape just got more sophisticated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Is the \u201cAuthentic Antics\u201d Malware?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Authentic Antics<\/strong> is a newly discovered malware toolkit engineered to <strong>gain and maintain access<\/strong> to Microsoft cloud services\u2014primarily <strong>Outlook and other Microsoft 365 applications<\/strong>. The malware is distinct in its ability to <strong>masquerade as legitimate user activity<\/strong>, avoiding detection from both users and endpoint protection tools.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Key Characteristics:<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Credential Harvesting<\/strong>: Displays realistic login windows to prompt users for their Microsoft credentials.<\/li>\n\n\n\n<li><strong>OAuth Token Theft<\/strong>: Steals authentication tokens used for persistent access to cloud services.<\/li>\n\n\n\n<li><strong>Data Exfiltration via Email<\/strong>: Sends stolen data to attacker-controlled email addresses using the victim\u2019s own account, <strong>without showing up in the sent folder<\/strong>.<\/li>\n\n\n\n<li><strong>No Command-and-Control (C2)<\/strong>: Omits traditional C2 channels to avoid detection by network monitoring tools.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This malware prioritizes <strong>stealth and persistence<\/strong>, making it particularly dangerous for organizations relying on Microsoft cloud infrastructure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How Does the Malware Work?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Authentic Antics cleverly blends into normal activity, avoiding red flags that typically expose malicious behavior. Here&#8217;s a simplified breakdown of how the attack unfolds:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 1: Initial Access<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The malware is likely delivered via phishing or other social engineering tactics. Once on the endpoint, it mimics standard Outlook behavior.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 2: Credential Interception<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Victims are presented with a <strong>fake login window<\/strong> designed to collect their credentials and <strong>OAuth tokens<\/strong>\u2014used by Microsoft services for authentication.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 3: Persistent Access<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">With tokens and credentials in hand, attackers gain <strong>persistent, session-based access<\/strong> to email accounts and associated Microsoft services without requiring repeated logins.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 4: Covert Exfiltration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The malware <strong>emails stolen data<\/strong> directly from the victim\u2019s account to actor-controlled inboxes\u2014<strong>without ever leaving a trace<\/strong> in the sent folder.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Discovery and Attribution<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The malware was discovered during the <strong>investigation of a cyber incident<\/strong> by Microsoft and <strong>NCC Group<\/strong>, a cybersecurity firm accredited by the NCSC. It was formally attributed to <strong>APT28<\/strong> due to the <strong>tools, tactics, and infrastructure<\/strong> aligning with previous GRU-linked activity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Paul Chichester, NCSC Director of Operations, emphasized:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\u201cThe use of Authentic Antics malware demonstrates the persistence and sophistication of the cyber threat posed by Russia\u2019s GRU. Organizations must not take this lightly.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Global Context: Russia\u2019s Continued Cyber Aggression<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The release of the Authentic Antics analysis coincides with <strong>UK sanctions<\/strong> against <strong>three GRU units<\/strong>\u2014Units 26165, 29155, and 74455\u2014and <strong>18 GRU officers<\/strong> involved in cyber and information warfare.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This isn\u2019t an isolated campaign:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>In <strong>May 2025<\/strong>, the NSA and its allies revealed a <strong>Russian campaign<\/strong> targeting <strong>Western logistics and technology companies<\/strong>.<\/li>\n\n\n\n<li>In <strong>June 2025<\/strong>, Ukraine\u2019s CERT-UA discovered a related malware strain, <strong>LameHug<\/strong>, also linked to APT28.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These events paint a consistent picture: <strong>Russian cyber operations remain active, global, and strategically aligned with the Kremlin\u2019s geopolitical goals<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why It Matters: Threat to Microsoft Cloud Users<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With more businesses and governments adopting Microsoft 365, vulnerabilities in this ecosystem represent a <strong>massive attack surface<\/strong>. Authentic Antics bypasses traditional security tools by:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Avoiding C2 traffic<\/strong><\/li>\n\n\n\n<li><strong>Using built-in Microsoft functionality<\/strong><\/li>\n\n\n\n<li><strong>Remaining invisible to users<\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The malware&#8217;s ability to persist using OAuth tokens and email exfiltration mechanisms highlights the <strong>critical need for Zero Trust architecture, identity monitoring, and advanced endpoint detection and response (EDR)<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Key Lessons for Organizations<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">1. <strong>Implement Multi-Factor Authentication (MFA)<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">While not foolproof, MFA can stop attackers even if they gain credentials.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. <strong>Monitor OAuth Usage<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Regularly review authorized applications and OAuth tokens in Microsoft 365 environments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. <strong>Harden Email Security<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Enable <strong>mail flow rules<\/strong>, anomaly detection, and exfiltration monitoring within Exchange Online.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. <strong>Conduct Regular Threat Hunting<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Go beyond reactive defenses. Use behavioral analytics and EDR solutions to find signs of unauthorized access or token misuse.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. <strong>Stay Informed<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Keep up with NCSC, CERT-UA, and other threat intelligence feeds to stay aware of emerging malware like Authentic Antics.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The emergence of <strong>Authentic Antics<\/strong> is yet another reminder of how <strong>sophisticated and persistent Russian cyber-espionage operations<\/strong> have become. By focusing on stealth, persistence, and cloud-native exploitation techniques, APT28 and similar groups are evolving faster than many organizations can respond.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Defending against these threats requires layered security<\/strong>, constant vigilance, and a deep understanding of how attackers exploit modern digital ecosystems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Governments and enterprises alike must act with urgency\u2014<strong>because in cyber warfare, invisibility is the most dangerous weapon.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The cyber threat landscape continues to evolve, with state-sponsored actors employing increasingly stealthy and sophisticated tactics. In a recent advisory, the UK\u2019s National Cyber Security Centre (NCSC) revealed the discovery of a new malware strain named &#8220;Authentic Antics&#8221;, attributed to the notorious Russian threat group APT28, also known as Fancy Bear and linked to Russia\u2019s [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":982,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[10],"tags":[390,391,130,16,392,393,394,395,396,397,398,399],"class_list":["post-567","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-apt28","tag-authentic-antics","tag-cyber-espionage","tag-cybersecurity","tag-fancy-bear","tag-gru","tag-malware","tag-microsoft-email","tag-nation-state-attacks","tag-ncsc","tag-oauth","tag-russia"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"The cyber threat landscape continues to evolve, with state-sponsored actors employing increasingly stealthy and sophisticated tactics. In a recent advisory, the UK\u2019s National Cyber Security Centre (NCSC) revealed the discovery of a new malware strain named &quot;Authentic Antics&quot;, attributed to the notorious Russian threat group APT28, also known as Fancy Bear and linked to Russia\u2019s\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"shubhrasharma665@gmail.com\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"News &amp; Update of Cyber Security World Globally | Securis360 -\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Russia Linked to New Malware Targeting Email Accounts for Espionage - News &amp; Update of Cyber Security World Globally | Securis360\" \/>\n\t\t<meta property=\"og:description\" content=\"The cyber threat landscape continues to evolve, with state-sponsored actors employing increasingly stealthy and sophisticated tactics. In a recent advisory, the UK\u2019s National Cyber Security Centre (NCSC) revealed the discovery of a new malware strain named &quot;Authentic Antics&quot;, attributed to the notorious Russian threat group APT28, also known as Fancy Bear and linked to Russia\u2019s\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-07-22T03:15:20+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-02-18T06:30:41+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/securis360\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@securis360\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Russia Linked to New Malware Targeting Email Accounts for Espionage - News &amp; Update of Cyber Security World Globally | Securis360\" \/>\n\t\t<meta name=\"twitter:description\" content=\"The cyber threat landscape continues to evolve, with state-sponsored actors employing increasingly stealthy and sophisticated tactics. In a recent advisory, the UK\u2019s National Cyber Security Centre (NCSC) revealed the discovery of a new malware strain named &quot;Authentic Antics&quot;, attributed to the notorious Russian threat group APT28, also known as Fancy Bear and linked to Russia\u2019s\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@securis360\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\\\/#blogposting\",\"name\":\"Russia Linked to New Malware Targeting Email Accounts for Espionage - News & Update of Cyber Security World Globally | Securis360\",\"headline\":\"Russia Linked to New Malware Targeting Email Accounts for Espionage\",\"author\":{\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/author\\\/shubhrasharma665gmail-com\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/securis360.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/Russia-Linked-to-New-Malware-Targeting-Email-Accounts-for-Espionage-1.png\",\"width\":1280,\"height\":720},\"datePublished\":\"2025-07-22T08:45:20+00:00\",\"dateModified\":\"2026-02-18T06:30:41+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\\\/#webpage\"},\"articleSection\":\"News, APT28, Authentic Antics, cyber espionage, Cybersecurity, Fancy Bear, GRU, malware, Microsoft email, nation-state attacks, NCSC, OAuth, Russia\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/securis360.com\\\/blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/securis360.com\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/category\\\/news\\\/#listItem\",\"name\":\"News\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/category\\\/news\\\/#listItem\",\"position\":2,\"name\":\"News\",\"item\":\"https:\\\/\\\/securis360.com\\\/blog\\\/category\\\/news\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\\\/#listItem\",\"name\":\"Russia Linked to New Malware Targeting Email Accounts for Espionage\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/securis360.com\\\/blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\\\/#listItem\",\"position\":3,\"name\":\"Russia Linked to New Malware Targeting Email Accounts for Espionage\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/category\\\/news\\\/#listItem\",\"name\":\"News\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/#organization\",\"name\":\"Securis360 Inc.\",\"description\":\"Securis360 is a global cybersecurity company providing Managed SOC, VAPT, SOC 2 Compliance, ISO 27001 Consulting, Cloud Security, SIEM, MDR, Incident Response and Cyber Risk Management services.\",\"url\":\"https:\\\/\\\/securis360.com\\\/blog\\\/\",\"telephone\":\"+16195593838\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/securis360.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/cropped-final-logo-05.png\",\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\\\/#organizationLogo\",\"width\":512,\"height\":512,\"caption\":\"Securis360 Logo\"},\"image\":{\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/securis360\",\"https:\\\/\\\/x.com\\\/securis360\",\"https:\\\/\\\/www.instagram.com\\\/securis360\",\"https:\\\/\\\/www.pinterest.com\\\/securis360\\\/\",\"https:\\\/\\\/www.youtube.com\\\/@Securis360\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/securis360\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/author\\\/shubhrasharma665gmail-com\\\/#author\",\"url\":\"https:\\\/\\\/securis360.com\\\/blog\\\/author\\\/shubhrasharma665gmail-com\\\/\",\"name\":\"shubhrasharma665@gmail.com\",\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/securis360.com\\\/blog\\\/wp-content\\\/litespeed\\\/avatar\\\/d9cfd1db106e641415395713203d73df.jpg?ver=1785406099\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\\\/#webpage\",\"url\":\"https:\\\/\\\/securis360.com\\\/blog\\\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\\\/\",\"name\":\"Russia Linked to New Malware Targeting Email Accounts for Espionage - News & Update of Cyber Security World Globally | Securis360\",\"description\":\"The cyber threat landscape continues to evolve, with state-sponsored actors employing increasingly stealthy and sophisticated tactics. In a recent advisory, the UK\\u2019s National Cyber Security Centre (NCSC) revealed the discovery of a new malware strain named \\\"Authentic Antics\\\", attributed to the notorious Russian threat group APT28, also known as Fancy Bear and linked to Russia\\u2019s\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/author\\\/shubhrasharma665gmail-com\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/author\\\/shubhrasharma665gmail-com\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/securis360.com\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/07\\\/Russia-Linked-to-New-Malware-Targeting-Email-Accounts-for-Espionage-1.png\",\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\\\/#mainImage\",\"width\":1280,\"height\":720},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\\\/#mainImage\"},\"datePublished\":\"2025-07-22T08:45:20+00:00\",\"dateModified\":\"2026-02-18T06:30:41+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/securis360.com\\\/blog\\\/\",\"name\":\"News & Update of Cyber Security World Globally | Securis360\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/securis360.com\\\/blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Russia Linked to New Malware Targeting Email Accounts for Espionage - News &amp; Update of Cyber Security World Globally | Securis360<\/title>\n\n","aioseo_head_json":{"title":"Russia Linked to New Malware Targeting Email Accounts for Espionage - News & Update of Cyber Security World Globally | Securis360","description":"The cyber threat landscape continues to evolve, with state-sponsored actors employing increasingly stealthy and sophisticated tactics. In a recent advisory, the UK\u2019s National Cyber Security Centre (NCSC) revealed the discovery of a new malware strain named \"Authentic Antics\", attributed to the notorious Russian threat group APT28, also known as Fancy Bear and linked to Russia\u2019s","canonical_url":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/#blogposting","name":"Russia Linked to New Malware Targeting Email Accounts for Espionage - News & Update of Cyber Security World Globally | Securis360","headline":"Russia Linked to New Malware Targeting Email Accounts for Espionage","author":{"@id":"https:\/\/securis360.com\/blog\/author\/shubhrasharma665gmail-com\/#author"},"publisher":{"@id":"https:\/\/securis360.com\/blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/securis360.com\/blog\/wp-content\/uploads\/2025\/07\/Russia-Linked-to-New-Malware-Targeting-Email-Accounts-for-Espionage-1.png","width":1280,"height":720},"datePublished":"2025-07-22T08:45:20+00:00","dateModified":"2026-02-18T06:30:41+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/#webpage"},"isPartOf":{"@id":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/#webpage"},"articleSection":"News, APT28, Authentic Antics, cyber espionage, Cybersecurity, Fancy Bear, GRU, malware, Microsoft email, nation-state attacks, NCSC, OAuth, Russia"},{"@type":"BreadcrumbList","@id":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/securis360.com\/blog#listItem","position":1,"name":"Home","item":"https:\/\/securis360.com\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/securis360.com\/blog\/category\/news\/#listItem","name":"News"}},{"@type":"ListItem","@id":"https:\/\/securis360.com\/blog\/category\/news\/#listItem","position":2,"name":"News","item":"https:\/\/securis360.com\/blog\/category\/news\/","nextItem":{"@type":"ListItem","@id":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/#listItem","name":"Russia Linked to New Malware Targeting Email Accounts for Espionage"},"previousItem":{"@type":"ListItem","@id":"https:\/\/securis360.com\/blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/#listItem","position":3,"name":"Russia Linked to New Malware Targeting Email Accounts for Espionage","previousItem":{"@type":"ListItem","@id":"https:\/\/securis360.com\/blog\/category\/news\/#listItem","name":"News"}}]},{"@type":"Organization","@id":"https:\/\/securis360.com\/blog\/#organization","name":"Securis360 Inc.","description":"Securis360 is a global cybersecurity company providing Managed SOC, VAPT, SOC 2 Compliance, ISO 27001 Consulting, Cloud Security, SIEM, MDR, Incident Response and Cyber Risk Management services.","url":"https:\/\/securis360.com\/blog\/","telephone":"+16195593838","logo":{"@type":"ImageObject","url":"https:\/\/securis360.com\/blog\/wp-content\/uploads\/2026\/03\/cropped-final-logo-05.png","@id":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/#organizationLogo","width":512,"height":512,"caption":"Securis360 Logo"},"image":{"@id":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/securis360","https:\/\/x.com\/securis360","https:\/\/www.instagram.com\/securis360","https:\/\/www.pinterest.com\/securis360\/","https:\/\/www.youtube.com\/@Securis360","https:\/\/www.linkedin.com\/company\/securis360"]},{"@type":"Person","@id":"https:\/\/securis360.com\/blog\/author\/shubhrasharma665gmail-com\/#author","url":"https:\/\/securis360.com\/blog\/author\/shubhrasharma665gmail-com\/","name":"shubhrasharma665@gmail.com","image":{"@type":"ImageObject","url":"https:\/\/securis360.com\/blog\/wp-content\/litespeed\/avatar\/d9cfd1db106e641415395713203d73df.jpg?ver=1785406099"}},{"@type":"WebPage","@id":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/#webpage","url":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/","name":"Russia Linked to New Malware Targeting Email Accounts for Espionage - News & Update of Cyber Security World Globally | Securis360","description":"The cyber threat landscape continues to evolve, with state-sponsored actors employing increasingly stealthy and sophisticated tactics. In a recent advisory, the UK\u2019s National Cyber Security Centre (NCSC) revealed the discovery of a new malware strain named \"Authentic Antics\", attributed to the notorious Russian threat group APT28, also known as Fancy Bear and linked to Russia\u2019s","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/securis360.com\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/#breadcrumblist"},"author":{"@id":"https:\/\/securis360.com\/blog\/author\/shubhrasharma665gmail-com\/#author"},"creator":{"@id":"https:\/\/securis360.com\/blog\/author\/shubhrasharma665gmail-com\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/securis360.com\/blog\/wp-content\/uploads\/2025\/07\/Russia-Linked-to-New-Malware-Targeting-Email-Accounts-for-Espionage-1.png","@id":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/#mainImage","width":1280,"height":720},"primaryImageOfPage":{"@id":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/#mainImage"},"datePublished":"2025-07-22T08:45:20+00:00","dateModified":"2026-02-18T06:30:41+00:00"},{"@type":"WebSite","@id":"https:\/\/securis360.com\/blog\/#website","url":"https:\/\/securis360.com\/blog\/","name":"News & Update of Cyber Security World Globally | Securis360","inLanguage":"en-US","publisher":{"@id":"https:\/\/securis360.com\/blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"News &amp; Update of Cyber Security World Globally | Securis360 -","og:type":"article","og:title":"Russia Linked to New Malware Targeting Email Accounts for Espionage - News &amp; Update of Cyber Security World Globally | Securis360","og:description":"The cyber threat landscape continues to evolve, with state-sponsored actors employing increasingly stealthy and sophisticated tactics. In a recent advisory, the UK\u2019s National Cyber Security Centre (NCSC) revealed the discovery of a new malware strain named &quot;Authentic Antics&quot;, attributed to the notorious Russian threat group APT28, also known as Fancy Bear and linked to Russia\u2019s","og:url":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/","article:published_time":"2025-07-22T03:15:20+00:00","article:modified_time":"2026-02-18T06:30:41+00:00","article:publisher":"https:\/\/www.facebook.com\/securis360","twitter:card":"summary_large_image","twitter:site":"@securis360","twitter:title":"Russia Linked to New Malware Targeting Email Accounts for Espionage - News &amp; Update of Cyber Security World Globally | Securis360","twitter:description":"The cyber threat landscape continues to evolve, with state-sponsored actors employing increasingly stealthy and sophisticated tactics. In a recent advisory, the UK\u2019s National Cyber Security Centre (NCSC) revealed the discovery of a new malware strain named &quot;Authentic Antics&quot;, attributed to the notorious Russian threat group APT28, also known as Fancy Bear and linked to Russia\u2019s","twitter:creator":"@securis360"},"aioseo_meta_data":{"post_id":"567","title":null,"description":null,"keywords":null,"keyphrases":{"focus":[],"additional":[]},"focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_custom_url":null,"og_image_custom_fields":null,"og_image_url":null,"og_image_width":null,"og_image_height":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_image_url":null,"twitter_title":null,"twitter_description":null,"schema_type":"default","schema_type_options":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"limit_modified_date":false,"ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-08-03 06:31:19","created":"2026-07-31 06:41:15","updated":"2026-08-03 06:31:19","reviewed_by":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/securis360.com\/blog\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/securis360.com\/blog\/category\/news\/\" title=\"News\">News<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tRussia Linked to New Malware Targeting Email Accounts for Espionage\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/securis360.com\/blog"},{"label":"News","link":"https:\/\/securis360.com\/blog\/category\/news\/"},{"label":"Russia Linked to New Malware Targeting Email Accounts for Espionage","link":"https:\/\/securis360.com\/blog\/russia-linked-to-new-malware-targeting-email-accounts-for-espionage\/"}],"_links":{"self":[{"href":"https:\/\/securis360.com\/blog\/wp-json\/wp\/v2\/posts\/567","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securis360.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securis360.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securis360.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/securis360.com\/blog\/wp-json\/wp\/v2\/comments?post=567"}],"version-history":[{"count":0,"href":"https:\/\/securis360.com\/blog\/wp-json\/wp\/v2\/posts\/567\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/securis360.com\/blog\/wp-json\/wp\/v2\/media\/982"}],"wp:attachment":[{"href":"https:\/\/securis360.com\/blog\/wp-json\/wp\/v2\/media?parent=567"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securis360.com\/blog\/wp-json\/wp\/v2\/categories?post=567"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securis360.com\/blog\/wp-json\/wp\/v2\/tags?post=567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}