UNK_AcademicFlare is a suspected Russia-aligned threat actor focused on compromising Microsoft 365 accounts through OAuth 2.0 device authorization abuse, commonly called device code phishing. The activity has been observed since at least September 2025 and is associated with account takeover operations against organizations in the United States and Europe. The actor has targeted government, think tanks, higher education, transportation, and related public-interest organizations, and has used compromised government and military email accounts to build rapport with intended victims before delivering phishing lures. The group’s tradecraft centers on social engineering that directs victims into legitimate Microsoft device login workflows using attacker-generated device codes. Campaigns have used spoofed cloud-sharing themes and rapport-building messages, including fictitious meetings or interview pretexts, to increase trust. By inducing victims to authorize attacker-controlled access through Microsoft’s legitimate authentication infrastructure, the actor can obtain tokens that enable persistent access, account takeover, and follow-on access to Microsoft 365 data and connected services. Reported downstream risks from this technique include data exfiltration, persistence, and lateral movement. UNK_AcademicFlare has been described as part of a broader wave of state-aligned adoption of device code phishing, particularly among Russia-aligned clusters. The actor’s targeting has included government officials, think tank researchers, university personnel, and in some reporting Ukrainian government and energy-related organizations, with emphasis on U.S. and European victims. The dominant assessed motivation is espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a Russian threat group that has used device code phishing attacks to hijack Microsoft accounts.
Named activity cluster attributed as Russia-aligned and linked to device code phishing attacks against Microsoft 365 identities.
Russia-aligned/suspected Russia-aligned phishing activity using Microsoft 365 device-code phishing to steal credentials and perform account takeovers.
UNK_AcademicFlare is a suspected Russia-aligned threat group conducting sophisticated social engineering and OAuth device code phishing campaigns targeting government officials, think tank researchers, and university staff.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.