Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Cybercriminals
  • Russian Hackers Abuse Microsoft 365 OAuth in Sophisticated Phishing Attacks
  • Cybercriminals

Russian Hackers Abuse Microsoft 365 OAuth in Sophisticated Phishing Attacks

Do Son April 24, 2025 3 minutes read
0
OAuth Phishing Microsoft 365 OAuth

Image: Volexity

Add Daily CyberSecurity as a preferred source on Google

Volexity has identified a series of advanced social engineering operations by suspected Russian threat actors targeting Microsoft 365 (M365) OAuth authentication flows. The campaigns, which began in March 2025, represent a concerning evolution in phishing techniques—leveraging legitimate Microsoft authentication infrastructure to gain unauthorized access to victim accounts.

“Volexity is currently tracking what is believed to be at least two Russian threat actors, which it tracks as UTA0352 and UTA0355, that are behind these attacks,” the report states.

UTA0352 primarily uses secure messaging apps like Signal and WhatsApp to impersonate diplomats and government officials. Victims are invited to join fake video calls discussing sensitive topics—especially the conflict in Ukraine—and are sent Microsoft OAuth URLs as part of the ruse.

Initial outreach messages sent by UTA0352 impersonating various identities on Signal (left) and WhatsApp (right) | Image: Volexity 

“The victim is asked to return the Microsoft-generated OAuth code back to the attacker… which ultimately allows access to the victim’s M365 account.”

In one example, targets received PDF instructions from the “Romanian Ministry of Foreign Affairs,” leading them to URLs like:

https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?...&redirect_uri=https://insiders.vscode.dev/redirect

These links point to first-party Microsoft services, including Visual Studio Code, to extract OAuth authorization codes. Once obtained, these codes are exchanged for access tokens—providing full access to the victim’s M365 resources.

In these phishing flows, the attackers cleverly abuse legitimate features of Microsoft’s OAuth implementation. “Clicking the link alone would not be enough… The code would need to be supplied back to the attacker,” Volexity explains.

In one scenario, users were redirected to a VS Code interface designed to expose the OAuth code in the browser’s address bar or dialog window. This code, valid for up to 60 days, grants access to Microsoft Graph APIs, potentially exposing all emails, files, and collaboration data.

The second threat actor, UTA0355, used a more elaborate multi-stage approach. It started with emails sent from a compromised Ukrainian government account to NGOs and human rights advocates, followed by social engineering via messaging apps.

“This time, the campaign started with an email from a legitimate, compromised Ukrainian Government email account… followed by messages sent via Signal and WhatsApp.”

Instead of accessing Graph APIs directly, UTA0355 targeted the Device Registration Service in Microsoft Entra ID (formerly Azure AD), registering a new device to the victim’s identity.

After this, the attacker socially engineered the target to approve a 2FA request, giving full control over the email account. Post-compromise activity revealed the email contents were downloaded from the newly registered machine.

Volexity offers numerous recommendations to identify and mitigate these attacks:

  • Alert on OAuth flows using client_id aebc6443-996d-45c2-90f0-388ff96faa56 with suspicious redirect URIs.
  • Block access to insiders.vscode.dev and vscode-redirect.azurewebsites.net if feasible.
  • Monitor for unusual device registrations in Microsoft Entra ID.
  • Educate users about unsolicited contact through secure messaging apps.
  • Implement conditional access policies restricting access to approved or managed devices.

Unlike conventional phishing that relies on fake websites or malware, these campaigns abuse first-party Microsoft infrastructure. The OAuth flow is technically legitimate, but users unknowingly grant attackers access by sharing sensitive tokens—a method harder to detect and even harder to defend against.

“The victim is only ever asked to interact with legitimate Microsoft 365 services, which users may inherently see as trustworthy,” Volexity warns.

Related Posts:

  • Phishing for Profits: Attackers Mine Crypto & Spam Through OAuth Apps
  • Volexity: Indian APT hacker organization Patchwork target US think tanks
  • Massive XSS Threat: Millions of Websites Vulnerable via OAuth Flaw
  • Russian Hackers Exploit Microsoft Device Code Authentication in Targeted Attacks Against M365 Accounts

Related coverage

  • Russian APT UTA0355 Steals Microsoft 365 OAuth Tokens via Fake Security Conference Lures and WhatsApp Support
  • Head Mare APT Exploits TrueConf Server Flaws to Deploy PhantomCore Backdoor
  • DarkCloud Stealer Evolves: New VB6 Obfuscation and Crypto Wallet Theft Make Malware More Dangerous Than Ever
  • TikTok for Business Under Siege: New Phishing Campaign Exploits “Login with Google”
  • DEF CON Attendee Suspected in Fake WiFi Attack Targeting Delta Flight 591 Passengers
  • Glitch Platform Abused: Phishing Campaigns Circumvent MFA and Target Credit Unions
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Takeover cyber-espionage cybersecurity Entra ID Microsoft 365 OAuth OAuth Abuse OAuth Phishing phishing Russian APT Russian threat actors social engineering UTA0352 UTA0355 Volexity

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-105192CVSS 9.8
    LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and...
    📅 Updated: Oct 7, 2026
  • CVE-2025-62877CVSS 9.8
    Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are using the...
    📅 Updated: Oct 7, 2026
  • CVE-2025-15018CVSS 9.8
    The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up...
    📅 Updated: Oct 7, 2026
  • CVE-2025-68637CVSS 9.1
    The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This...
    📅 Updated: Oct 7, 2026
  • CVE-2025-47552CVSS 9.8
    Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This issue affects DZS...
    📅 Updated: Oct 7, 2026
  • CVE-2025-32303CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind...
    📅 Updated: Oct 7, 2026
  • CVE-2025-69222CVSS 9.1
    LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF)...
    📅 Updated: Oct 7, 2026
  • CVE-2025-23504CVSS 9.8
    Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allows Authentication Abuse.This issue...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.