logo

Russian Hackers Spoof European Events in Targeted Phishing Attacks

ID: e290bf11-b16f-5c26-a7c9-33533484fc5b

STIX ID: report--e290bf11-b16f-5c26-a7c9-33533484fc5b

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2025-12-05

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Russian-linked actor UTA0355 is running targeted phishing campaigns that impersonate European security events to trick victims into OAuth and Device Code flows, capture tokens and device codes, and gain long‑term API-level access to Microsoft 365 and Google accounts; the intrusions are stealthy (device-registration reuse, proxy access) and include observable indicators (spoofed domains, captured login URLs) alongside suggested detection rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.