Also known as: UTA0355, tracked as, Midnight Blizzard, NOBELIUM, UNC2452, Cozy Bear, impersonate European officials, use platforms like Signal, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Lotus Blossom, Spring Dragon, ST Group, DRAGONFISH, BRONZE ELGIN, ATK1, G0030, Red Salamander, Lotus BLossom, Billbug, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, DarkHalo, StellarParticle, Solar Phoenix
UTA0352 is an adversarial unit believed to have Russian origins, actively engaging in OAuth 2.0 abuse against Microsoft 365 environments. The actor deploys spear‑phishing emails that masquerade as trusted service prompts—often referencing legitimate authentication flows—to extract Microsoft authorization codes. These accounts are then used to create unauthorized user profiles or exfiltrate data from Office 365 and Google Workspace services. In addition to straightforward credential collection, UTA0352 leverages cloud infrastructure such as VPS instances and serverless functions to host malicious payloads, expand command & control capabilities, and conduct automated searches using tools like MailSniper. They frequently embed malicious code in container or cloud images for persistence, exploit third‑party DNS systems, and even target SAP NetWeaver vulnerabilities (CVE‑2025-31324) to deploy web shells. Social engineering plays a central role: the group often reaches out to victims via Signal and WhatsApp, impersonating European government representatives, thereby increasing perceived legitimacy. The combination of phishing, cloud exploitation, and account takeover indicates a well‑coordinated, multi‑stage operation that prioritizes stealth and scalability.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Russian threat actor UTA0352 utilizes sophisticated OAuth 2.0 phishing campaigns to hijack Microsoft 365 user credentials by impersonating European officials and leveraging messaging apps such as Signal and WhatsApp. The group targets a broad spectrum of NGOs, media, defense, and critical‑infrastructure sectors linked to Ukraine, using stolen authorization codes to gain persistent access to corporate clouds. Their methods indicate a focus on credential theft and lateral movement rather than destructive sabotage.
Goals & Targeting
The primary strategic objective appears to be the systematic acquisition and use of privileged credentials across diverse sectors—especially those tied to Ukrainian interests and European NGOs—to facilitate long‑term data exfiltration and leverage compromised accounts for potential secondary operations. By infiltrating Microsoft 365, Exchange, and Google Workspace environments, UTA0352 gains access to high‑value email archives, contacts, and sensitive documents that can be weaponized for political or commercial purposes. Their broad target list suggests a desire to harvest a wide array of data types while maintaining operational secrecy through legitimate cloud services and social engineering techniques.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UTA0352 campaigns exhibit a high frequency of phishing blasts tied to Microsoft 365 OAuth fraud, typically delivered via mass email and followed by targeted WhatsApp or Signal messages. Operations appear to be low‑noise but high‑volume, with attackers exploiting cloud infrastructures for rapid scaling and automated credential harvesting. Victims are primarily NGOs, media outlets, defense contractors, and other entities linked to Ukrainian policy concerns; the group has also recently expanded reach into broader sectors such as critical infrastructure and education. Previous similar operations attributed to Cozy Bear/UNC2452 suggest a long‑standing pattern of exploiting legitimate authentication workflows for stealthy persistence.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Attribution to a Russian organized group is moderate due to corroborating phishing patterns and infrastructure usage, yet definitive malware samples directly tied to UTA0352 are lacking. Operational scope beyond credential theft remains partially inferred; detailed motives and long‑term objectives stay ambiguous. Evidence gaps include the absence of confirmed destructive payloads, limited visibility into lateral movement techniques beyond account takeover scripts, and unclear post‑exfiltration usage of harvested data.
No campaigns linked yet.
No observed data linked yet.
41
Techniques
43
Tools
0
Campaigns
38
IOCs
0
Observed Data
13
Tactics