UTA0352

Origin
RU
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:21:57

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:ua country_code:ro

Context

UTA0352 is a Russian threat actor attributed to phishing campaigns that exploit Microsoft OAuth 2.0 authentication workflows, often impersonating government officials to lure targets into providing sensitive information. The actor has been observed using malicious URLs disguised as legitimate services, such as a Romanian government authentication system. UTA0352 has also targeted Microsoft Teams and employed social engineering tactics via messaging platforms like Signal and WhatsApp. Volexity assesses with medium confidence that UTA0352 is involved in operations themed around Ukraine, targeting individuals and organizations historically associated with Russian threat activities.

Reports & references

  • volexity.com — Phishing For Codes Russian Threat Actors Target Microsoft 365 Oauth Workflows (report)

External references