216.73.217.22

Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication

· Published 14/02/2025 02:48 · Modified 14/02/2025 10:46

Export JSON

Essential information

Published
14/02/2025 02:48
Modified
14/02/2025 10:46
Tags
2025-02-14 device code authentication microsoft 365 oauth phishing russia social engineering spear-phishing
Related entities
1 intrusion sets (apt), 12 techniques (mitre), 5 others

Description

Russian threat actors are conducting social-engineering and campaigns to compromise accounts using . This method has proven more effective than traditional techniques. Campaigns have targeted organizations with politically-themed lures, impersonating entities like the US Department of State and Ukrainian Ministry of Defence. Three distinct threat actors (UTA0304, CozyLarch/APT29, and UTA0307) have been identified using similar tactics but with slight variations in their approach and infrastructure. The attacks exploit users' unfamiliarity with the process, making it challenging to recognize as . Detection methods and preventive measures are available but often not implemented by organizations.

External references