Skip to content
September 14, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Cybercriminals
  • Russian Hackers Abuse Microsoft 365 OAuth in Sophisticated Phishing Attacks
  • Cybercriminals

Russian Hackers Abuse Microsoft 365 OAuth in Sophisticated Phishing Attacks

Do Son April 24, 2025 3 minutes read
0
OAuth Phishing Microsoft 365 OAuth

Image: Volexity

Add Daily CyberSecurity as a preferred source on Google

Volexity has identified a series of advanced social engineering operations by suspected Russian threat actors targeting Microsoft 365 (M365) OAuth authentication flows. The campaigns, which began in March 2025, represent a concerning evolution in phishing techniques—leveraging legitimate Microsoft authentication infrastructure to gain unauthorized access to victim accounts.

“Volexity is currently tracking what is believed to be at least two Russian threat actors, which it tracks as UTA0352 and UTA0355, that are behind these attacks,” the report states.

UTA0352 primarily uses secure messaging apps like Signal and WhatsApp to impersonate diplomats and government officials. Victims are invited to join fake video calls discussing sensitive topics—especially the conflict in Ukraine—and are sent Microsoft OAuth URLs as part of the ruse.

Initial outreach messages sent by UTA0352 impersonating various identities on Signal (left) and WhatsApp (right) | Image: Volexity 

“The victim is asked to return the Microsoft-generated OAuth code back to the attacker… which ultimately allows access to the victim’s M365 account.”

In one example, targets received PDF instructions from the “Romanian Ministry of Foreign Affairs,” leading them to URLs like:

https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?...&redirect_uri=https://insiders.vscode.dev/redirect

These links point to first-party Microsoft services, including Visual Studio Code, to extract OAuth authorization codes. Once obtained, these codes are exchanged for access tokens—providing full access to the victim’s M365 resources.

In these phishing flows, the attackers cleverly abuse legitimate features of Microsoft’s OAuth implementation. “Clicking the link alone would not be enough… The code would need to be supplied back to the attacker,” Volexity explains.

In one scenario, users were redirected to a VS Code interface designed to expose the OAuth code in the browser’s address bar or dialog window. This code, valid for up to 60 days, grants access to Microsoft Graph APIs, potentially exposing all emails, files, and collaboration data.

The second threat actor, UTA0355, used a more elaborate multi-stage approach. It started with emails sent from a compromised Ukrainian government account to NGOs and human rights advocates, followed by social engineering via messaging apps.

“This time, the campaign started with an email from a legitimate, compromised Ukrainian Government email account… followed by messages sent via Signal and WhatsApp.”

Instead of accessing Graph APIs directly, UTA0355 targeted the Device Registration Service in Microsoft Entra ID (formerly Azure AD), registering a new device to the victim’s identity.

After this, the attacker socially engineered the target to approve a 2FA request, giving full control over the email account. Post-compromise activity revealed the email contents were downloaded from the newly registered machine.

Volexity offers numerous recommendations to identify and mitigate these attacks:

  • Alert on OAuth flows using client_id aebc6443-996d-45c2-90f0-388ff96faa56 with suspicious redirect URIs.
  • Block access to insiders.vscode.dev and vscode-redirect.azurewebsites.net if feasible.
  • Monitor for unusual device registrations in Microsoft Entra ID.
  • Educate users about unsolicited contact through secure messaging apps.
  • Implement conditional access policies restricting access to approved or managed devices.

Unlike conventional phishing that relies on fake websites or malware, these campaigns abuse first-party Microsoft infrastructure. The OAuth flow is technically legitimate, but users unknowingly grant attackers access by sharing sensitive tokens—a method harder to detect and even harder to defend against.

“The victim is only ever asked to interact with legitimate Microsoft 365 services, which users may inherently see as trustworthy,” Volexity warns.

Related Posts:

  • Phishing for Profits: Attackers Mine Crypto & Spam Through OAuth Apps
  • Volexity: Indian APT hacker organization Patchwork target US think tanks
  • Massive XSS Threat: Millions of Websites Vulnerable via OAuth Flaw
  • Russian Hackers Exploit Microsoft Device Code Authentication in Targeted Attacks Against M365 Accounts

Related coverage

  • The Fake Job Trap: Microsoft Exposes the ‘Contagious Interview’ Campaign Targeting Developers
  • Microsoft Teams Exploited for Silent Enterprise Takeovers
  • AWS Password Spraying Campaign Targets Root Accounts
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Takeover cyber-espionage cybersecurity Entra ID Microsoft 365 OAuth OAuth Abuse OAuth Phishing phishing Russian APT Russian threat actors social engineering UTA0352 UTA0355 Volexity

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42018CVSS 7.5
    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-84869CVSS 9.9
    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote...
    CISA KEV📅 Added to KEV: Sep 11, 2026
  • CVE-2026-20079CVSS 10.0
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2025-25249CVSS 8.1
    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-87491
    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-59178CVSS 9.8
    ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management...
  • CVE-2026-90945CVSS 9.8
    Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing...
  • CVE-2026-90942CVSS 9.6
    Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private...
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco...
  • CVE-2026-76443CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality,...
  • CVE-2026-76441CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality,...
  • CVE-2026-76440CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality,...
  • CVE-2026-20353CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality,...
  • CVE-2026-57131CVSS 9.8
    PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router...
  • CVE-2026-57124CVSS 9.8
    PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.