UTA0352 is a suspected Russian threat cluster tracked for highly targeted Microsoft 365 OAuth phishing operations active from March 2025. It has targeted NGOs, human-rights advocates, and individuals and organizations connected to Ukraine. The actor impersonates diplomats, government officials, and European political representatives through Signal and WhatsApp, using purported private meetings or Ukraine-related video calls as lures. UTA0352 abuses legitimate Microsoft OAuth workflows and trusted first-party applications rather than attacker-controlled credential-harvesting infrastructure. Victims are directed through legitimate Microsoft authentication experiences and socially engineered to disclose Microsoft-generated OAuth authorization codes. The actor exchanges captured codes for access tokens, enabling access to Microsoft 365 resources through Microsoft Graph, including email and potentially other data available to the compromised user. This tradecraft can evade controls focused on conventional credential phishing because it relies on valid authentication, authorization flows, and first-party cloud services. UTA0352 is tracked alongside UTA0355, another suspected Russian cluster operating against similar Ukraine- and human-rights-related targets. UTA0355 has been observed using device-registration and multifactor-authentication social engineering, but that activity should not be treated as confirmed UTA0352 tradecraft. Possible relationships between these clusters and APT29 have not been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Использует OAuth 2.0-ориентированную социальную инженерию, включая технику ConsentFix, чтобы получать авторизационные коды и доступ через first-party приложения Microsoft без классического consent prompt.
Conducting a sophisticated OAuth phishing campaign abusing Microsoft Entra ID / Microsoft 365 OAuth authorization code flows and trusted first-party Microsoft application client IDs (e.g., VSCode, Microsoft Authentication Broker) to harvest authorization codes/tokens, impersonate users, register devices, obtain PRTs, and exfiltrate data via Microsoft Graph (e.g., Outlook email, SharePoint access).
Conducted OAuth authorization-code phishing against NGO users, abusing first-party Microsoft clients including Visual Studio Code and Microsoft Authentication Broker. The activity harvested authorization codes and tokens, used ROADtools/ROADtx to access Microsoft Graph resources, and in one workflow registered devices and obtained Primary Refresh Tokens for persistent access.
Russia-linked threat actors are targeting individuals and organizations related to Ukraine and human rights to compromise Microsoft 365 accounts using social engineering and official infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.