Friday, 19 December 2025

Russia-Linked Hackers Use Microsoft 365 Device Code Phishing for Account Takeovers

iT4iNT SERVER A suspected Russia-aligned group has been attributed to a phishing campaign that employs device code authentication workflows to steal victims' Microsoft 365 credentials and conduct account takeover attacks.
The activity, ongoing since September 2025, is being tracked by Proofpoint under the moniker UNK_AcademicFlare.
The attacks involve using compromised email addresses belonging to government VDS VPS Cloud


http://dlvr.it/TPw9hP

No comments:

Post a Comment

Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline

iT4iNT SERVER A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email cre...