CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2104

As cited

Copy frozen at (site build).

threat intel

Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks

Russian threat actor UTA0355 is conducting sophisticated phishing campaigns that impersonate legitimate European security conferences, including the Belgrade Security Conference and Brussels Indo-Pacific Dialogue, to compromise Microsoft 365 and Google accounts. The attacks combine rapport-building via email and messaging apps, fake professional websites, and abuse of Microsoft OAuth and Device Code authentication workflows to steal credentials. Victims are socially engineered to grant unauthorized account access after being primed through fake event registrations and multi-channel communication.

Why it matters: Security teams managing Microsoft 365 and Google environments need to implement OAuth phishing defenses and authentication hardening immediately, as employees attending legitimate international events are being actively targeted with credential harvesting campaigns using legitimate conference details.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks

Russian threat actor UTA0355 is conducting sophisticated phishing campaigns that impersonate legitimate European security conferences, including the Belgrade Security Conference and Brussels Indo-Pacific Dialogue, to compromise Microsoft 365 and Google accounts. The attacks combine rapport-building via email and messaging apps, fake professional websites, and abuse of Microsoft OAuth and Device Code authentication workflows to steal credentials. Victims are socially engineered to grant unauthorized account access after being primed through fake event registrations and multi-channel communication.

Why it matters: Security teams managing Microsoft 365 and Google environments need to implement OAuth phishing defenses and authentication hardening immediately, as employees attending legitimate international events are being actively targeted with credential harvesting campaigns using legitimate conference details.

VendorsMicrosoftGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary