Russian threat actor known for Microsoft OAuth 2.0 phishing campaigns impersonating government officials.
Analyst brief
UTA0352 is a Russian threat actor known for phishing campaigns that exploit Microsoft OAuth 2.0 authentication workflows, often impersonating government officials to steal credentials. This actor targets individuals and organizations historically associated with Russian threat activities, particularly within Ukraine-themed operations. Key TTPs include the use of malicious URLs disguised as legitimate authentication systems, alongside social engineering delivered via messaging platforms such as Signal, WhatsApp, and Microsoft Teams. Defenders should scrutinize unexpected OAuth consent requests, verify contacts from messaging platforms, and monitor network traffic for phishing indicators.
UTA0352
unknown
UTA0352 is a Russian threat actor attributed to phishing campaigns that exploit Microsoft OAuth 2.0 authentication workflows, often impersonating government officials to lure targets into providing sensitive information. The actor has been observed using malicious URLs disguised as legitimate services, such as a Romanian government authentication system. UTA0352 has also targeted Microsoft Teams and employed social engineering tactics via messaging platforms like Signal and WhatsApp. Volexity assesses with medium confidence that UTA0352 is involved in operations themed around Ukraine, targeting individuals and organizations historically associated with Russian threat activities.
What are the key TTPs of the Russian threat actor UTA0352?+
UTA0352 exploits Microsoft OAuth 2.0 authentication workflows, impersonates government officials, and uses malicious URLs, fake authentication systems, and social engineering tactics via messaging platforms such as Signal, WhatsApp, and Microsoft Teams.
What is the targeting profile of the UTA0352 actor?+
UTA0352 targets individuals and organizations historically associated with Russian threat activities, particularly within Ukraine-themed operations.