Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UTA0352

Also known as: UTA0355, tracked as, Midnight Blizzard, NOBELIUM, UNC2452, Cozy Bear, impersonate European officials, use platforms like Signal, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Lotus Blossom, Spring Dragon, ST Group, DRAGONFISH, BRONZE ELGIN, ATK1, G0030, Red Salamander, Lotus BLossom, Billbug, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, DarkHalo, StellarParticle, Solar Phoenix

Description

UTA0352 is an adversarial unit believed to have Russian origins, actively engaging in OAuth 2.0 abuse against Microsoft 365 environments. The actor deploys spear‑phishing emails that masquerade as trusted service prompts—often referencing legitimate authentication flows—to extract Microsoft authorization codes. These accounts are then used to create unauthorized user profiles or exfiltrate data from Office 365 and Google Workspace services. In addition to straightforward credential collection, UTA0352 leverages cloud infrastructure such as VPS instances and serverless functions to host malicious payloads, expand command & control capabilities, and conduct automated searches using tools like MailSniper. They frequently embed malicious code in container or cloud images for persistence, exploit third‑party DNS systems, and even target SAP NetWeaver vulnerabilities (CVE‑2025-31324) to deploy web shells. Social engineering plays a central role: the group often reaches out to victims via Signal and WhatsApp, impersonating European government representatives, thereby increasing perceived legitimacy. The combination of phishing, cloud exploitation, and account takeover indicates a well‑coordinated, multi‑stage operation that prioritizes stealth and scalability.

Goals & Targeting

Targeted Sectors

Media
Non profit
Government
Defense
Financial services
Telecommunications
Healthcare
Critical infrastructure
Retail
Education
Transportation
Manufacturing
Energy
Think tank
Hospitality
Information technology

Targeted Countries / Regions

UA
RU
CN
US
KP
GB
TW
KR
IR
PK
ES
DE
NL
PL
JP
FR
RO
IL
BR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

Russian threat actor UTA0352 utilizes sophisticated OAuth 2.0 phishing campaigns to hijack Microsoft 365 user credentials by impersonating European officials and leveraging messaging apps such as Signal and WhatsApp. The group targets a broad spectrum of NGOs, media, defense, and critical‑infrastructure sectors linked to Ukraine, using stolen authorization codes to gain persistent access to corporate clouds. Their methods indicate a focus on credential theft and lateral movement rather than destructive sabotage.

Goals & Targeting

The primary strategic objective appears to be the systematic acquisition and use of privileged credentials across diverse sectors—especially those tied to Ukrainian interests and European NGOs—to facilitate long‑term data exfiltration and leverage compromised accounts for potential secondary operations. By infiltrating Microsoft 365, Exchange, and Google Workspace environments, UTA0352 gains access to high‑value email archives, contacts, and sensitive documents that can be weaponized for political or commercial purposes. Their broad target list suggests a desire to harvest a wide array of data types while maintaining operational secrecy through legitimate cloud services and social engineering techniques.

Enhanced Description

Key Capabilities

  • Phishing for OAuth 2.0 authentication codes via legitimate Microsoft 365 workflows
  • Social engineering using messaging platforms such as Signal and WhatsApp to increase message legitimacy
  • Impersonation of European government officials to gain victim trust in phishing outreach
  • Exploitation of compromised email accounts for initial access
  • Compromise of cloud accounts and use of cloud storage services for tool upload and exfiltration
  • Leveraging cloud infrastructure (VPS, serverless functions) to host malicious content or command & control
  • Abuse of third‑party domains, DNS, and servers to facilitate phishing and lateral movement
  • Building botnets from compromised machines to scale attacks
  • Establishing new local and domain user accounts using net user /add for persistence and lateral movement
  • Targeting Exchange, Office 365, and Google Workspace environments to harvest email data
  • Injecting malicious code into cloud or container images to establish persistence
  • Exploiting SAP NetWeaver CVE‑2025-31324 to deploy web shells and install Brute Ratel RAT

MITRE ATT&CK Tactics

Initial Access
Credential Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Discovery
Lateral Movement
Collection
Exfiltration

ATT&CK Techniques

T1037
T1557
T1583
T1613
T1123
T1543
T1547
T1119
T1115
T1071
T1555
T1659
T1010
T1560
T1185
T1580
T1217
T1092
T1595
T1548
T1087
T1059
T1020
T1609
T1584
T1612
T1586
T1619
T1554
T1098
T1110
T1531
T1671
T1197
T1650
T1651
T1134
T1136
T1526
T1538
T1566.002

Software / Tooling

Havex RAT
Signal
WhatsApp
Crimson RAT
ROADTools
netsh
PowerShell
BITS
rundll32
MSBuild
Hook

Campaigns & Victims

UTA0352 campaigns exhibit a high frequency of phishing blasts tied to Microsoft 365 OAuth fraud, typically delivered via mass email and followed by targeted WhatsApp or Signal messages. Operations appear to be low‑noise but high‑volume, with attackers exploiting cloud infrastructures for rapid scaling and automated credential harvesting. Victims are primarily NGOs, media outlets, defense contractors, and other entities linked to Ukrainian policy concerns; the group has also recently expanded reach into broader sectors such as critical infrastructure and education. Previous similar operations attributed to Cozy Bear/UNC2452 suggest a long‑standing pattern of exploiting legitimate authentication workflows for stealthy persistence.

IOC Patterns

  • Domain
  • File
  • URL
  • OAuth 2.0 redirect URI pattern
  • Microsoft authentication code URL pattern

Recommended Actions

  • Implement multi‑factor authentication for all Microsoft 365 accounts
  • Configure OAuth consent boundaries to limit third‑party app access
  • Monitor and block suspicious Azure AD OAuth redirect URIs
  • Enforce strict email filtering rules and educate users on spear‑phishing linked to legitimate services
  • Verify authorization code requests via secure, out‑of‑band channels
  • Regularly review newly created or privileged user accounts in domain
  • Implement network segmentation to isolate critical cloud services from external exposure
  • Monitor DNS changes for unauthorized domain or record alterations

Suggested Tags

phishing
Microsoft 365
OAuth abuse
Russian threat actor
UTA0352
Spearphishing Link
Signal
WhatsApp
cloud compromise
credential theft

Confidence Assessment

Attribution to a Russian organized group is moderate due to corroborating phishing patterns and infrastructure usage, yet definitive malware samples directly tied to UTA0352 are lacking. Operational scope beyond credential theft remains partially inferred; detailed motives and long‑term objectives stay ambiguous. Evidence gaps include the absence of confirmed destructive payloads, limited visibility into lateral movement techniques beyond account takeover scripts, and unclear post‑exfiltration usage of harvested data.

ATT&CK Techniques

Exfiltration
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 18 URL 2

References

  1. cert.europa.eu — Cited by web research for: impersonate European officials
  2. attack.mitre.org — Cited by web research for: services
  3. research.checkpoint.com — Cited by web research for: Lotus Blossom
  4. www.elastic.co — Cited by web research for: Leverage
  5. www.volexity.com — Cited by web research for: Visual Studio Code
  6. attack.mitre.org — Cited by web research for: Process Hollowing
  7. https://login.microsoftonline.com/organizations/oauth2/v2.0 — Cited by AI analysis.

Intel Summary

41

Techniques

43

Tools

0

Campaigns

38

IOCs

0

Observed Data

13

Tactics

Tags

Critical Infrastructure
Phishing
Government Targeting
phishing
Microsoft 365
OAuth abuse
Russian threat actor
UTA0352
Spearphishing Link
Signal
WhatsApp
cloud compromise
credential theft

Details

Type
Unknown
Primary Motivation
Ideology
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.