logo

Beware of video call links that are attempts to steal Microsoft 365 access, researchers tell NGOs

ID: 0a2cea09-8f88-58cb-9f63-d50762964137

STIX ID: report--0a2cea09-8f88-58cb-9f63-d50762964137

Feed Name: The Record from Recorded Future News

Threat Score
70/100

Date Published: 2025-04-22

Date Updated: 2026-05-01

...
...

Volexity observed Russia-linked actors (UTA0352 and UTA0355) running highly targeted social-engineering campaigns that send bogus video-call URLs over secure messaging apps to NGO staff; victims who provide the resulting OAuth codes enable attackers to generate Microsoft 365 access tokens and gain account access. The activity, first seen in March, targets NGOs and think tanks connected to Ukraine and leverages OAuth/device-code authentication workflows, prompting recommendations for heightened user vigilance and training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.