Russian Hackers Spoof European Events in Targeted Phishing Attacks
ID: e290bf11-b16f-5c26-a7c9-33533484fc5b
STIX ID: report--e290bf11-b16f-5c26-a7c9-33533484fc5b
Feed Name: cybersecurityNews.com
Threat Score
Russian-linked actor UTA0355 is running targeted phishing campaigns that impersonate European security events to trick victims into OAuth and Device Code flows, capture tokens and device codes, and gain long‑term API-level access to Microsoft 365 and Google accounts; the intrusions are stealthy (device-registration reuse, proxy access) and include observable indicators (spoofed domains, captured login URLs) alongside suggested detection rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
