UTA0307
UTA0307 is a Russia-aligned threat actor cluster referenced in reporting on Microsoft 365-focused phishing and authentication abuse. The content directly associates UTA0307 with device code phishing activity, alongside other Russia-aligned groups including Storm-2372, APT29, UTA0304, and UNK_AcademicFlare. This tradecraft abuses Microsoft’s legitimate OAuth device authorization flow by sending victims to the real microsoft[.]com/devicelogin endpoint and tricking them into entering attacker-supplied device codes, resulting in issuance of access and refresh tokens that can enable persistent account access even after password resets. Reported targeting tied to these broader Russia-aligned device code phishing operations includes Microsoft 365 users at organizations in the United States, Canada, Australia, New Zealand, and Germany, spanning construction, non-profit, real estate, manufacturing, financial services, healthcare, legal, and government sectors, as well as government, think tanks, higher education, transportation, Ukraine-related, and human rights-linked targets in the U.S. and Europe. The content also notes that Volexity did not rule out possible links between separate Microsoft OAuth social-engineering activity and APT29, UTA0304, and UTA0307, but does not provide a firm attribution for that activity to UTA0307. Known alias in the provided content: uta0307.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Capital Goods
- Financial Services
- Health Care Equipment & Services
- Commercial & Professional Services
- Software & Services
- Real Estate Management & Development
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
- 🇨🇦 Canada
- 🇦🇺 Australia
- 🇳🇿 New Zealand
- 🇩🇪 Germany
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attributed as a Russia-aligned activity cluster conducting device code phishing operations targeting Microsoft 365 identities.
UTA0307 is a Russia-aligned threat actor cluster using device code phishing to compromise Microsoft 365 accounts.
Referenced only as a potentially related threat cluster; no distinct TTPs or operations are attributed to UTA0307 in the provided content.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.