UTA0355 is a Russian threat actor known for phishing campaigns using fake video conference invites targeting Ukraine.
Analyst brief
UTA0355 is a Russian threat actor conducting phishing campaigns targeting individuals and organizations associated with Ukraine. Their primary TTPs involve sending fake video conference invites via email, followed by Signal/WhatsApp messages to build trust, and then tricking victims into approving MFA on a malicious M365 login page. Defenders should be vigilant for unsolicited conference invitations, off-platform communications, and suspicious M365 authentication prompts.
UTA0355
unknown
UTA0355 is a Russian threat actor that conducts phishing campaigns targeting individuals and organizations associated with Ukraine. The actor initiates contact via email, inviting targets to a video conference, and follows up through Signal or WhatsApp to enhance legitimacy. After establishing communication, UTA0355 prompts victims to log in via a malicious M365 URL, subsequently requesting approval for a 2FA authentication to access email data. Volexity assesses with high confidence that UTA0355 successfully registered devices and downloaded email data from compromised accounts.