Russian Hackers Exploit Microsoft OAuth to Target Ukraine Allies via Signal and WhatsApp

Russian Hackers Exploit Microsoft OAuth to Target Ukraine Allies via Signal and WhatsApp
Summary: Multiple suspected Russia-linked threat actors are targeting individuals and organizations with connections to Ukraine to gain unauthorized access to Microsoft 365 accounts using sophisticated social engineering techniques. Volexity’s analysis reveals new methods leveraging legitimate Microsoft OAuth workflows, where adversaries impersonate European officials to deceive victims. There are at least two tracked threat clusters, UTA0352 and UTA0355, employing these tactics to exploit vulnerabilities and gain access to sensitive information.

Affected: Microsoft 365 accounts

Keypoints :

  • Attacks use social engineering to trick users into providing Microsoft OAuth codes.
  • Messaging apps like Signal and WhatsApp facilitate initiating contact with potential victims.
  • Compromised Ukrainian government accounts have been exploited in these schemes.
  • Techniques involve redirecting users to official Microsoft URLs, raising risks of account hijacking.
  • Organizations are encouraged to audit device registration and educate users on risks from unsolicited messaging.

Source: https://thehackernews.com/2025/04/russian-hackers-exploit-microsoft-oauth.html