
Russian Cyber Actors Exploit Microsoft Oauth To Breach Ukraine-Linked Organisations
Russian-linked cyber operatives have been leveraging legitimate Microsoft OAuth 2.0 authentication processes to compromise Microsoft 365 accounts of individuals and organisations associated with Ukraine and human rights advocacy. Cybersecurity firm Volexity has been monitoring this activity since early March 2025, identifying two threat clusters, UTA0352 and UTA0355, as the primary actors behind these campaigns.
The attackers initiate contact by impersonating European political officials, reaching out to targets via encrypted messaging platforms like WhatsApp and Signal. They invite recipients to participate in private meetings or discussions related to Ukraine, providing links that redirect to legitimate Microsoft login portals. Upon authentication, users are directed to an in-browser version of Visual Studio Code, where Microsoft OAuth codes are displayed. Believing these codes are necessary to join the meeting, victims inadvertently share them with the attackers.
These authorization codes, valid for up to 60 days, grant the threat actors access to the victims' Microsoft 365 accounts. In some instances, the attackers use the codes to register new devices to the victims' Microsoft Entra ID , enabling persistent access to emails and other sensitive data. The attackers further complicate detection by routing login activities through proxy networks that match the victims' geographical locations.
In one notable case, UTA0355 utilized a compromised Ukrainian government email account to send spear-phishing emails, followed by messages on Signal and WhatsApp. These communications invited targets to join a video conference related to Ukraine's efforts in prosecuting atrocity crimes. The attackers then requested the victims to approve a two-factor authentication request, ostensibly to access a SharePoint instance associated with the conference, thereby bypassing additional security measures.
See also Majority of CIOs Overspend on Cloud Budgets, Survey Reveals Notice an issue? Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com . We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity. Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept
any responsibility or liability for the accuracy, content, images,
videos, licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright
issues related to this article, kindly contact the provider above.
Most popular stories
Market Research

- Ex-Cardano CMO Maverick Adam Bates Jumps Ship To XION As Chief Marketing Officer
- SPAYZ.Io To Roll Out Payment Solutions In Key African Markets
- Edgen Launches AI Super App, Democratizing Institutional-Grade Crypto Market Intelligence
- AB DAO And AB Charity Foundation Join Forces To Build A Trustworthy Infrastructure And Promote Global Philanthropic Transformation
- Flipster Makes Esports Debut As Official Crypto Exchange Partner Of TALON's Dota 2 Team, Powering A New Era Of Fan Engagement
- Primexbt Expands MT5 Offering With Over 100 New Trading Instruments
Comments
No comment