Beware of video call links that are attempts to steal Microsoft 365 access, researchers tell NGOs
ID: 0a2cea09-8f88-58cb-9f63-d50762964137
STIX ID: report--0a2cea09-8f88-58cb-9f63-d50762964137
Feed Name: The Record from Recorded Future News
Volexity observed Russia-linked actors (UTA0352 and UTA0355) running highly targeted social-engineering campaigns that send bogus video-call URLs over secure messaging apps to NGO staff; victims who provide the resulting OAuth codes enable attackers to generate Microsoft 365 access tokens and gain account access. The activity, first seen in March, targets NGOs and think tanks connected to Ukraine and leverages OAuth/device-code authentication workflows, prompting recommendations for heightened user vigilance and training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
