UTA0352UTA0352

Also known as: UTA0352

Known aliases
1

Profile

UTA0352 is a Russian threat actor attributed to phishing campaigns that exploit Microsoft OAuth 2.0 authentication workflows, often impersonating government officials to lure targets into providing sensitive information. The actor has been observed using malicious URLs disguised as legitimate services, such as a Romanian government authentication system. UTA0352 has also targeted Microsoft Teams and employed social engineering tactics via messaging platforms like Signal and WhatsApp. Volexity assesses with medium confidence that UTA0352 is involved in operations themed around Ukraine, targeting individuals and organizations historically associated with Russian threat activities.

Aliases· 1

UTA0352

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
UTA0355
Actor
UAC-0102
Actor
TA2552
Actor
UAC-0185
Actor
UAC-0215
Actor
UAC-0063
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.