As cited
Citation snapshot as of .
threat intel
Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication
Russian threat actors conducted targeted social-engineering and spear-phishing campaigns against Microsoft 365 accounts starting in mid-January 2025, using device code authentication as a lesser-known compromise method. Volexity identified multiple campaigns impersonating officials from the US State Department, Ukrainian Ministry of Defence, and other organizations to trick users into granting authentication access. The attacks proved more effective than typical targeted phishing and have been attributed to Russian actors including those tracked as CozyLarch, UTA0304, and UTA0307.
Why it matters: Organizations and government agencies using Microsoft 365 face elevated risk from persistent Russian nation-state phishing and device code attacks; security teams should review authentication logs for suspicious device code flows and reinforce user awareness on impersonation tactics targeting senior staff and officials.
- Source published
- First seen by Cybersecurity Tracker