Also known as: UTA0352, Midnight Blizzard, tracked as, APT28, Pawn Storm, Fancy Bear, NOBELIUM, UNC2452, Cozy Bear, Lotus Blossom, impersonate European officials, use platforms like Signal, APT29, Peach Sandstorm, Sednit, APT33
UTI0355—also known in some reports as Midnight Blizzard or UTA0352—has emerged as a focused cyber‑espionage actor aligned with Russian state objectives. Since early 2025 the group has directed spear‑phishing attacks at Ukrainian government, non‑profit, academic, and corporate targets, often masquerading as European diplomatic officials to lower user resistance. The attack chain typically begins with an inbound email inviting recipients to a video or conference call, followed by contact through messaging apps such as Signal or WhatsApp that reference the same official. Victims are then lured into clicking on a Microsoft 365 login URL or a malicious Windows/browsers update link, which initiates a legitimate OAuth 2.0 authentication flow. The actor manipulates users into approving a seemingly innocuous 2‑factor request, after which it registers a rogue device within Entra ID and exploits the acquired tokens to access corporate email and Azure AD resources. UTI0355 has demonstrated proficiency in leveraging the ROADtools framework (roadrecon for account discovery, roadtx for token acquisition) to elevate privileges and facilitate lateral movement across Microsoft 365 tenants without triggering standard MFA callbacks. The group’s tactics combine social engineering with cloud‑native exploitation, allowing rapid compromise while minimizing forensic footprints. Defenders should implement granular OAuth application controls, enforce strong MFA methods that require physical or app‑based verification beyond simple link approval, and monitor anomalous device registration events in Entra ID. Awareness training targeting spear‑phishing via official communication channels is essential to reduce the success rate of these campaigns.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UTA0355 is a Russian‑linked threat actor primarily targeting Ukrainian entities through highly tailored spear‑phishing campaigns that impersonate European officials and exploit Microsoft 365 OAuth flows. The group leverages device registration hijacking to gain persistent, MFA‑bypass access to corporate mailboxes and Azure AD resources, enabling rapid data exfiltration. Defensive posture should focus on strict MFA enforcement, OAuth scope control, and vigilant monitoring of device registration events.
Goals & Targeting
UTA0355’s strategic objective appears to be intelligence gathering on Ukrainian political, defense, and research entities. By compromising Microsoft 365 accounts they obtain privileged email access, user information, and lateral movement capabilities through Azure AD token abuse. The actor systematically expands its reach by requesting additional contacts from compromised users, thereby widening exposure without engaging in overt weaponized attacks. This approach supports long‑term espionage missions while maintaining plausible deniability. Target selection is heavily skewed toward organizations with national security relevance—government ministries, think tanks, educational institutes, and critical‑infrastructure firms—reflecting a deliberate effort to harvest policy, strategic communications, and internal documents that can inform Russian geopolitical objectives. The use of impersonated European officials creates a false sense of legitimacy, enabling the group to tap into established diplomatic networks and acquire high‑value information without detection. By focusing on cloud platforms and exploiting legitimate authentication mechanisms they achieve stealthy persistence and data exfiltration across multiple sectors. Key capabilities
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UTI0355 has been actively conducting campaigns since early 2025, with a high tempo that includes rapid expansion of compromised networks by requesting additional contacts from initial victims. Victim profiles include Ukrainian government agencies, research institutions, and non‑profits, as evidenced by the targeted Centre for Security, Diplomacy, and Strategy at Vrije Universiteit Brussel. The actor employs coordinated social engineering—email followed by messaging app follow‑up—to lower the attacker's chances of detection while leveraging cloud-native exploitation (Microsoft 365 OAuth abuse, Entra ID device registration). Notable operations feature the use of fake Windows or browser update links to deliver payloads and the deployment of ROADtools for token hijacking, enabling lateral movement and persistence without requiring traditional malware. The campaign patterns reflect a blend of targeted phishing, credential harvesting, and cloud infrastructure exploitation designed to facilitate covert intelligence gathering.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment of UTA0355’s tactics and targets is based on publicly disclosed analyses from Volexity, security vendor reports, and observed attack patterns. Confidence in the actor’s use of Microsoft OAuth abuse, device registration exploitation, and ROADtools for token hijacking is high due to multiple independent confirmations. However, gaps remain regarding the exact timeline of operations, full scope across all potential victim sectors, and whether related aliases such as UTA0352 or Midnight Blizzard refer to distinct groups or sub‑units within a broader campaign.
No campaigns linked yet.
No observed data linked yet.
8
Techniques
43
Tools
0
Campaigns
31
IOCs
0
Observed Data
7
Tactics