Also known as: cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, tracked as, Storm-2372, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork
UNK_AcademicFlare employs a carefully orchestrated social engineering strategy that hinges on Microsoft 365 OAuth device authorization. Attackers first obtain valid email addresses from government and military sources, presenting benign correspondence that builds rapport before delivering a device‑code link or QR code via a spoofed Azure tenant email. Victims are asked to enter the code on what appears to be an official Microsoft login page, but in reality the link is routed through a Cloudflare Worker domain that mirrors OneDrive’s interface and captures credentials. Once valid access tokens are obtained, the group leverages automated polling of Microsoft’s token endpoint to refresh access tokens, providing ongoing administrative rights. They deploy PlugX for stealthy persistence, enabling lateral movement across M365 tenant resources, while phishing automation tools such as SquarePhish and Graphish allow rapid scaling. Adversary‑in‑the‐Middle techniques—using reverse proxies and fabricated Azure App Registrations—enable credential harvesting in cases where MFA is enforced. The attacks are highly tailored: they target sectors considered of strategic value, including defense, transportation, higher education, and think tanks, often tying the message content to Russia/Ukraine geopolitical themes to increase credibility. The group’s operational tempo appears sustained during late 2025, with indicators that they are still actively refining tooling and expanding geographic reach.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNK_AcademicFlare is a suspected Russia‑aligned espionage group that primarily targets government, defense, and academic organizations across the US and Europe by spearphishing Microsoft 365 users through malicious OAuth device code flows. Their campaigns use compromised email accounts and Cloudflare Worker URLs to spoof OneDrive links, enabling MFA bypass and credential theft. The actor deploys PlugX malware, SquarePhish/Graphish phishing kits, and reverse‑proxy techniques to achieve lateral movement and persistence within victim networks.
Goals & Targeting
The primary strategic objective of UNK_AcademicFlare is state‑aligned espionage aimed at extracting sensitive information from critical government and defense infrastructures. By compromising Microsoft 365 accounts they gain early access to email, calendars, documents, and internal collaboration tools, which can be used for further reconnaissance, exfiltration, or to plant additional malware such as PlugX for persistence. Their targeting focus on academic institutions offers a low‑defense entry point into research that may influence defense procurement or policy decisions.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNK_AcademicFlare’s campaigns exhibit a high degree of automation and low visibility. They leverage publicly available phishing kits to rapidly scale attacks across multiple user accounts while maintaining an aggressive operational tempo. Victim profiles tend toward public‑sector entities with high sensitivity, particularly those relying on Microsoft 365 for collaboration. The group frequently updates its infrastructure—changing Cloudflare Worker domains and using rotated credentials—to evade detection. Historical activity indicates coordinated operations from 2025 onward, suggesting a sustained effort supported by state resources. Notable past operations include the September‑2025 surge of device code phishing targeting U.S. homeland security agencies and a separate wave against European transportation regulators. In both cases, attackers succeeded in stealing MFA tokens, compromising accounts, and installing plug‑and‑play malware to maintain persistence. Their use of AI‑powered spearphishing narratives tied to Russia/Ukraine conflicts has proven effective at gaining initial trust. Defense analysts note that the group’s primary value lies in early compromise of privileged accounts, which unlocks a broad range of subsequent attack vectors, including lateral movement via Office 365 groups and data exfiltration through cloud drives.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provides a solid foundation for identifying UNK_AcademicFlare as an active Russia‑aligned group using OAuth device code phishing. Confirmation of specific capabilities—such as PlugX deployment, usage of SquarePhish and Graphish kits, and deployment of Cloudflare Worker spoofing—is supported by multiple reports. However, gaps remain regarding the full range of malware families in use, detailed persistence techniques beyond PlugX, and the precise geographic scope of active operations. The confidence level is moderate; more recent intel would help refine timelines and operational patterns.
No campaigns linked yet.
No observed data linked yet.
16
Techniques
44
Tools
0
Campaigns
39
IOCs
0
Observed Data
8
Tactics