Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNK_AcademicFlare

Also known as: cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, tracked as, Storm-2372, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork

Description

UNK_AcademicFlare employs a carefully orchestrated social engineering strategy that hinges on Microsoft 365 OAuth device authorization. Attackers first obtain valid email addresses from government and military sources, presenting benign correspondence that builds rapport before delivering a device‑code link or QR code via a spoofed Azure tenant email. Victims are asked to enter the code on what appears to be an official Microsoft login page, but in reality the link is routed through a Cloudflare Worker domain that mirrors OneDrive’s interface and captures credentials. Once valid access tokens are obtained, the group leverages automated polling of Microsoft’s token endpoint to refresh access tokens, providing ongoing administrative rights. They deploy PlugX for stealthy persistence, enabling lateral movement across M365 tenant resources, while phishing automation tools such as SquarePhish and Graphish allow rapid scaling. Adversary‑in‑the‐Middle techniques—using reverse proxies and fabricated Azure App Registrations—enable credential harvesting in cases where MFA is enforced. The attacks are highly tailored: they target sectors considered of strategic value, including defense, transportation, higher education, and think tanks, often tying the message content to Russia/Ukraine geopolitical themes to increase credibility. The group’s operational tempo appears sustained during late 2025, with indicators that they are still actively refining tooling and expanding geographic reach.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Telecommunications
Energy
Education
Aerospace
Media
Think tank
Information technology
Healthcare
Pharmaceutical
Manufacturing
Transportation
Maritime
Chemical
Entertainment
Hospitality
Mining
Nuclear
Gaming
Legal services
Critical infrastructure
Retail
Construction
Food agriculture

Targeted Countries / Regions

US
CN
GB
RU
IN
JP
KR
DE
IR
FR
CA
SA
TW
IL
TR
AU
PK
KZ
UA
ES
PL
SG
VN
NL
BR
IT
BY
AE
IQ
MX
RO
SY
AZ
EG
LB

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

UNK_AcademicFlare is a suspected Russia‑aligned espionage group that primarily targets government, defense, and academic organizations across the US and Europe by spearphishing Microsoft 365 users through malicious OAuth device code flows. Their campaigns use compromised email accounts and Cloudflare Worker URLs to spoof OneDrive links, enabling MFA bypass and credential theft. The actor deploys PlugX malware, SquarePhish/Graphish phishing kits, and reverse‑proxy techniques to achieve lateral movement and persistence within victim networks.

Goals & Targeting

The primary strategic objective of UNK_AcademicFlare is state‑aligned espionage aimed at extracting sensitive information from critical government and defense infrastructures. By compromising Microsoft 365 accounts they gain early access to email, calendars, documents, and internal collaboration tools, which can be used for further reconnaissance, exfiltration, or to plant additional malware such as PlugX for persistence. Their targeting focus on academic institutions offers a low‑defense entry point into research that may influence defense procurement or policy decisions.

Enhanced Description

Key Capabilities

  • Microsoft 365 OAuth device code phishing campaigns
  • Compromised email address spearphishing with benign outreach
  • Spoofing OneDrive links via Cloudflare Worker domains
  • Exploitation of the device authorization flow as an MFA bypass
  • Automated token endpoint polling to refresh access tokens
  • Reverse‑proxy (Adversary‑in‑the‑Middle) capturing credentials
  • Fabrication of Azure App Registrations with fake client IDs and certificates
  • Use of PlugX malware for persistence and lateral movement
  • Automation via SquarePhish and Graphish phishing kits
  • QR code phishing embedded in emails

MITRE ATT&CK Tactics

Initial Access
Credential Access
Lateral Movement
Persistence
Defense Evasion

ATT&CK Techniques

T1566.002
T1078
T1566.001
T1528
T1594.002
T1181
T1015
T1600

Software / Tooling

PlugX
SquarePhish
SquarePhishV2
SquarePhish2
Graphish
Shamoon

Campaigns & Victims

UNK_AcademicFlare’s campaigns exhibit a high degree of automation and low visibility. They leverage publicly available phishing kits to rapidly scale attacks across multiple user accounts while maintaining an aggressive operational tempo. Victim profiles tend toward public‑sector entities with high sensitivity, particularly those relying on Microsoft 365 for collaboration. The group frequently updates its infrastructure—changing Cloudflare Worker domains and using rotated credentials—to evade detection. Historical activity indicates coordinated operations from 2025 onward, suggesting a sustained effort supported by state resources. Notable past operations include the September‑2025 surge of device code phishing targeting U.S. homeland security agencies and a separate wave against European transportation regulators. In both cases, attackers succeeded in stealing MFA tokens, compromising accounts, and installing plug‑and‑play malware to maintain persistence. Their use of AI‑powered spearphishing narratives tied to Russia/Ukraine conflicts has proven effective at gaining initial trust. Defense analysts note that the group’s primary value lies in early compromise of privileged accounts, which unlocks a broad range of subsequent attack vectors, including lateral movement via Office 365 groups and data exfiltration through cloud drives.

IOC Patterns

  • OAuth Device Authorization URL phishing targeting Microsoft 365
  • Compromised email address spearphishing with spoofed Azure tenant sender
  • Malicious URLs and QR codes embedded in emails
  • Cloudflare Worker domains mimicking legitimate OneDrive links
  • Fake Azure App Registration capturing login credentials
  • Token theft via automated OAuth device flow polling
  • MFA redemption through attacker‑controlled pages

Recommended Actions

  • Implement strict controls on Microsoft Device Code grant flows, such as whitelisting approved applications and enforcing usage policies.
  • Deploy real‑time monitoring of OAuth token issuance events and flag anomalies (e.g., simultaneous requests from new locations).
  • Educate users about OTPs that appear in unfamiliar web pages and train them to verify the authenticity of one‑click sign‑in URLs.
  • Block or sandbox Cloudflare Worker domains known to be used for phishing, and apply stricter outbound filtering against suspicious redirect hosts.
  • Validate sender email domain integrity using SPF/DKIM/DMARC before permitting user interaction with attachments or links.
  • Deploy endpoint detection solutions that detect PlugX activity and other known persistence mechanisms.
  • Leverage threat intelligence feeds from vendors such as Rescana, Proofpoint, or Mandiant to keep IOC lists current.
  • Restrict external app registrations in Azure AD and enforce MFA for privileged roles even when using OAuth flows.

Suggested Tags

Russia-aligned
State-sponsored
Microsoft 365 phishing
OAuth Device Code Phishing
MFA Bypass
PlugX malware
SquarePhish tool
Graphish kit
QR code phishing
Adversary-in-the-Middle
Spearphishing Link
Cloudflare Worker Spoof
Social engineering
Defense targeting
Academic targeting

Confidence Assessment

The available data provides a solid foundation for identifying UNK_AcademicFlare as an active Russia‑aligned group using OAuth device code phishing. Confirmation of specific capabilities—such as PlugX deployment, usage of SquarePhish and Graphish kits, and deployment of Cloudflare Worker spoofing—is supported by multiple reports. However, gaps remain regarding the full range of malware families in use, detailed persistence techniques beyond PlugX, and the precise geographic scope of active operations. The confidence level is moderate; more recent intel would help refine timelines and operational patterns.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 12 Email Address 2 IPv4 Address 1 URL 5

References

  1. misp-galaxy.org — Cited by web research for: cpyy
  2. www.cybersecuritydive.com — Cited by web research for: Storm-2372
  3. mallory.ai — Cited by web research for: T1078
  4. www.proofpoint.com — Cited by web research for: Graphish
  5. chintangurjar.com — Cited by web research for: Gaming
  6. www.rescana.com — Cited by web research for: Critical Infrastructure

Intel Summary

16

Techniques

44

Tools

0

Campaigns

39

IOCs

0

Observed Data

8

Tactics

Tags

Critical Infrastructure
Phishing
Government Targeting
APT
espionage
government
higher_education
Russia-aligned
State-sponsored
Microsoft 365 phishing
OAuth Device Code Phishing
MFA Bypass
PlugX malware
SquarePhish tool
Graphish kit
QR code phishing
Adversary-in-the-Middle
Spearphishing Link
Cloudflare Worker Spoof
Social engineering
Defense targeting
Academic targeting

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.