Russian APT UTA0355 Steals Microsoft 365 OAuth Tokens via Fake Security Conference Lures and WhatsApp Support

Russian APT UTA0355 Steals Microsoft 365 OAuth Tokens via Fake Security Conference Lures and WhatsApp Support

A Russian threat actor, UTA0355, conducts targeted phishing campaigns impersonating international security events to steal Microsoft 365 credentials. The group employs advanced social engineering tactics and manipulates OAuth workflows, leveraging compromised accounts for increased trust. #UTA0355 #BelgradeSecurityConference #BrusselsIndoPacificDialogue #MicrosoftOAuth

Keypoints

  • UTA0355 creates realistic fake websites for high-profile conferences to deceive victims.
  • The group uses a patient, personalized approach, building rapport before sending phishing links.
  • They offer live support via messaging apps to guide victims through authentication.

  • Attacks exploit Microsoft’s OAuth workflows to obtain persistent access tokens without stealing passwords.
  • Using compromised accounts from legitimate organizations enhances attack credibility and effectiveness.

Read More: https://securityonline.info/russian-apt-uta0355-steals-microsoft-365-oauth-tokens-via-fake-security-conference-lures-and-whatsapp-support/