Russian-linked threat actor UTA0352 targeted NGOs with Microsoft 365 OAuth phishing that impersonated trusted Microsoft first-party applications, including Visual Studio Code and Microsoft Authentication Broker. The operation sought authorization codes that could be exchanged for Microsoft Graph access tokens; one observed path used Authentication Broker and the Device Registration Service to obtain a refresh token, register an attacker-controlled device, and mint a Microsoft Entra ID Primary Refresh Token (PRT).
A PRT is a long-lived, device-bound Entra credential used to provide SSO and obtain tokens for multiple cloud applications. If attackers gain code execution or access to an authenticated Azure AD/Entra-joined Windows user context, they may be able to request PRT-derived token material through BrowserCore.exe and obtain reusable refresh tokens that can preserve MFA and device-compliance claims. Defenders should correlate Entra sign-in, audit, and Microsoft Graph logs for session IDs reused from different IP addresses, anomalous Authentication Broker-to-Device Registration Service token activity, scripted device registrations, and refresh-token-to-PRT transitions; endpoint telemetry should also flag suspicious BrowserCore.exe and Microsoft account token-provider activity.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
The campaign operators used captured OAuth material and ROADtools to obtain tokens, download Outlook email, and access SharePoint resources through Microsoft Graph. In the device-registration path, they obtained refresh-token material, registered an Entra ID device, and minted a PRT for persistent access; Volexity reported a victim's 2FA approval was followed by email access through SharePoint.
Russian-linked threat actor UTA0352 targeted NGOs with customized Microsoft Entra ID OAuth authorization URLs that impersonated trusted Microsoft first-party applications, harvesting authorization codes and security tokens.
Microsoft Entra ID stopped allowing Primary Refresh Token (PRT) cookies to be requested without an SSO nonce, preventing the previously described nonce-less cookie workflow.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourcevolexity.com
Open sourcedirkjanm.io
Open sourceposts.specterops.io
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.