CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2109

As cited

Copy frozen at (site build).

threat intel

Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication

Russian threat actors conducted targeted social-engineering and spear-phishing campaigns against Microsoft 365 accounts starting in mid-January 2025, using device code authentication as a lesser-known compromise method. Volexity identified multiple campaigns impersonating officials from the US State Department, Ukrainian Ministry of Defence, and other organizations to trick users into granting authentication access. The attacks proved more effective than typical targeted phishing and have been attributed to Russian actors including those tracked as CozyLarch, UTA0304, and UTA0307.

Why it matters: Organizations and government agencies using Microsoft 365 face elevated risk from persistent Russian nation-state phishing and device code attacks; security teams should review authentication logs for suspicious device code flows and reinforce user awareness on impersonation tactics targeting senior staff and officials.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication

Russian threat actors conducted targeted social-engineering and spear-phishing campaigns against Microsoft 365 accounts starting in mid-January 2025, using device code authentication as a lesser-known compromise method. Volexity identified multiple campaigns impersonating officials from the US State Department, Ukrainian Ministry of Defence, and other organizations to trick users into granting authentication access. The attacks proved more effective than typical targeted phishing and have been attributed to Russian actors including those tracked as CozyLarch, UTA0304, and UTA0307.

Why it matters: Organizations and government agencies using Microsoft 365 face elevated risk from persistent Russian nation-state phishing and device code attacks; security teams should review authentication logs for suspicious device code flows and reinforce user awareness on impersonation tactics targeting senior staff and officials.

VendorsMicrosoft
Actorsapt29midnight blizzard
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary