logo

Hackers abuse OAuth 2.0 workflows to hijack Microsoft 365 accounts

ID: a089170c-1da4-5a37-b36f-bd96a85b7bb3

STIX ID: report--a089170c-1da4-5a37-b36f-bd96a85b7bb3

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-04-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Russian-linked threat actors UTA0352 and UTA0355 are conducting targeted OAuth 2.0 phishing campaigns to hijack Microsoft 365 accounts of Ukrainian and human-rights-related organizations by impersonating officials and contacting victims over Signal/WhatsApp. Attackers trick victims into supplying long-lived authorization codes via a Visual Studio Code web landing page and then social-engineer MFA approvals to register devices in Microsoft Entra ID, enabling persistent access; Volexity recommends blocking insiders.vscode.dev and vscode-redirect.azurewebsites.net, monitoring the VS Code client_id, and enforcing conditional access to approved devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.