CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 2109

As cited

Citation snapshot as of .

threat intel

Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication

Russian threat actors conducted targeted social-engineering and spear-phishing campaigns against Microsoft 365 accounts starting in mid-January 2025, using device code authentication as a lesser-known compromise method. Volexity identified multiple campaigns impersonating officials from the US State Department, Ukrainian Ministry of Defence, and other organizations to trick users into granting authentication access. The attacks proved more effective than typical targeted phishing and have been attributed to Russian actors including those tracked as CozyLarch, UTA0304, and UTA0307.

Why it matters: Organizations and government agencies using Microsoft 365 face elevated risk from persistent Russian nation-state phishing and device code attacks; security teams should review authentication logs for suspicious device code flows and reinforce user awareness on impersonation tactics targeting senior staff and officials.

Source published
First seen by Cybersecurity Tracker

Source attribution