CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Phishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth Workflows

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2107

As cited

Copy frozen at (site build).

threat intel

Phishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth Workflows

Since early March 2025, Russian threat actors tracked as UTA0352 and UTA0355 have conducted targeted social engineering campaigns against Microsoft 365 users, particularly those working on Ukraine-related issues at NGOs and human rights organizations. The attackers impersonate European political officials via Signal and WhatsApp, then send OAuth phishing links claiming to be for video conference access, requesting victims return Microsoft-generated authentication codes. This represents a shift from earlier Device Code Authentication phishing attacks, with the threat actors now abusing other legitimate M365 OAuth workflows to compromise accounts.

Why it matters: Organizations and individuals engaged in Ukraine advocacy, human rights work, and diplomatic activities face heightened risk of account compromise and data theft; security teams should review OAuth authentication logs, disable suspicious sessions, and train staff on this multi-step phishing technique that requires both code generation and user cooperation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Phishing for Codes: Russian Threat Actors Target Microsoft 365 OAuth Workflows

Since early March 2025, Russian threat actors tracked as UTA0352 and UTA0355 have conducted targeted social engineering campaigns against Microsoft 365 users, particularly those working on Ukraine-related issues at NGOs and human rights organizations. The attackers impersonate European political officials via Signal and WhatsApp, then send OAuth phishing links claiming to be for video conference access, requesting victims return Microsoft-generated authentication codes. This represents a shift from earlier Device Code Authentication phishing attacks, with the threat actors now abusing other legitimate M365 OAuth workflows to compromise accounts.

Why it matters: Organizations and individuals engaged in Ukraine advocacy, human rights work, and diplomatic activities face heightened risk of account compromise and data theft; security teams should review OAuth authentication logs, disable suspicious sessions, and train staff on this multi-step phishing technique that requires both code generation and user cooperation.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary