Russian threat actors are conducting sophisticated phishing campaigns targeting Microsoft 365 accounts through Device Code Authentication, with recent attacks focusing on political themes around the new US administration. Multiple actors, including suspected CozyLarch (APT29), are using social engineering and spear-phishing to impersonate government officials and research institutions, achieving higher success rates than traditional phishing methods.

https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/

#cybersecurity #phishing #microsoft365 #apt #russia

Reply to this note

Please Login to reply.

Discussion

No replies yet.