RU

UTA0355UTA0355

Also known as: UTA0355

Origin
RU
Known aliases
1

Profile

UTA0355 is a Russian threat actor that conducts phishing campaigns targeting individuals and organizations associated with Ukraine. The actor initiates contact via email, inviting targets to a video conference, and follows up through Signal or WhatsApp to enhance legitimacy. After establishing communication, UTA0355 prompts victims to log in via a malicious M365 URL, subsequently requesting approval for a 2FA authentication to access email data. Volexity assesses with high confidence that UTA0355 successfully registered devices and downloaded email data from compromised accounts.

Aliases· 1

UTA0355

References

  1. https://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UTA0352
Actor
UAC-0185
Actor
UAC-0215
Actor
UAC-0102
Actor
Cyber Serp
Actor
TA2552
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.