As cited
Copy frozen at (site build).
threat intel
Phishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth Workflows
Since early March 2025, Russian threat actors tracked as UTA0352 and UTA0355 have conducted targeted social engineering campaigns against Microsoft 365 users, particularly those working on Ukraine-related issues at NGOs and human rights organizations. The attackers impersonate European political officials via Signal and WhatsApp, then send OAuth phishing links claiming to be for video conference access, requesting victims return Microsoft-generated authentication codes. This represents a shift from earlier Device Code Authentication phishing attacks, with the threat actors now abusing other legitimate M365 OAuth workflows to compromise accounts.
Why it matters: Organizations and individuals engaged in Ukraine advocacy, human rights work, and diplomatic activities face heightened risk of account compromise and data theft; security teams should review OAuth authentication logs, disable suspicious sessions, and train staff on this multi-step phishing technique that requires both code generation and user cooperation.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Phishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth Workflows
Since early March 2025, Russian threat actors tracked as UTA0352 and UTA0355 have conducted targeted social engineering campaigns against Microsoft 365 users, particularly those working on Ukraine-related issues at NGOs and human rights organizations. The attackers impersonate European political officials via Signal and WhatsApp, then send OAuth phishing links claiming to be for video conference access, requesting victims return Microsoft-generated authentication codes. This represents a shift from earlier Device Code Authentication phishing attacks, with the threat actors now abusing other legitimate M365 OAuth workflows to compromise accounts.
Why it matters: Organizations and individuals engaged in Ukraine advocacy, human rights work, and diplomatic activities face heightened risk of account compromise and data theft; security teams should review OAuth authentication logs, disable suspicious sessions, and train staff on this multi-step phishing technique that requires both code generation and user cooperation.
- Source published
- First seen by Cybersecurity Tracker