As cited
Copy frozen at (site build).
threat intel
Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks
Russian threat actor UTA0355 is conducting sophisticated phishing campaigns that impersonate legitimate European security conferences, including the Belgrade Security Conference and Brussels Indo-Pacific Dialogue, to compromise Microsoft 365 and Google accounts. The attacks combine rapport-building via email and messaging apps, fake professional websites, and abuse of Microsoft OAuth and Device Code authentication workflows to steal credentials. Victims are socially engineered to grant unauthorized account access after being primed through fake event registrations and multi-channel communication.
Why it matters: Security teams managing Microsoft 365 and Google environments need to implement OAuth phishing defenses and authentication hardening immediately, as employees attending legitimate international events are being actively targeted with credential harvesting campaigns using legitimate conference details.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks
Russian threat actor UTA0355 is conducting sophisticated phishing campaigns that impersonate legitimate European security conferences, including the Belgrade Security Conference and Brussels Indo-Pacific Dialogue, to compromise Microsoft 365 and Google accounts. The attacks combine rapport-building via email and messaging apps, fake professional websites, and abuse of Microsoft OAuth and Device Code authentication workflows to steal credentials. Victims are socially engineered to grant unauthorized account access after being primed through fake event registrations and multi-channel communication.
Why it matters: Security teams managing Microsoft 365 and Google environments need to implement OAuth phishing defenses and authentication hardening immediately, as employees attending legitimate international events are being actively targeted with credential harvesting campaigns using legitimate conference details.
- Source published
- First seen by Cybersecurity Tracker