logo

Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication

ID: a35f8ccd-efff-5121-a6f2-9e1d15cfd91d

STIX ID: report--a35f8ccd-efff-5121-a6f2-9e1d15cfd91d

Feed Name: Volexity Blog

Threat Score
85/100

Date Published: 2025-02-13

Date Updated: 2026-05-01

...
...

Volexity details multiple highly targeted spear-phishing campaigns attributed to Russia-aligned actors (CozyLarch, UTA0304, UTA0307) that socially engineer victims into using Microsoft Device Code OAuth (device code flow) to grant persistent access to Microsoft 365 accounts; the report includes campaign themes and lures (Teams invites, Element/Signal outreach), infrastructure and IoCs, observed data exfiltration from compromised accounts, and practical detection and mitigation recommendations (Entra/Sign-in log filters and conditional access to block device code flow).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.