Russia-Linked Group Uses Device Code Phishing to Steal M365 Credentials

Russia-Aligned UNK_AcademicFlare Group Exploits Microsoft 365 Device Code Authentication in Widespread Phishing Campaign Targeting Government and Critical Sectors

  • A Russia-aligned threat group named UNK_AcademicFlare has conducted a phishing campaign since September 2025 targeting Microsoft 365 users.
  • The attacks misuse compromised email accounts from government and military organizations to target sectors like government, think tanks, higher education, and transportation in the U.S. and Europe.
  • The phishing scheme exploits Microsoft’s device code authentication flow to hijack account access tokens and take over victim accounts.
  • Both state-aligned and criminal actors, including the e-crime group TA2723, have adopted this tactic, supported by widely available phishing kits and tools like Graphish and SquarePhish.
  • Countermeasures include implementing Conditional Access policies to block or restrict device code authentication for users.

Since September 2025, a suspected Russia-aligned group known as UNK_AcademicFlare has executed a phishing campaign targeting Microsoft 365 credentials. The campaign mainly impacts entities in government, think tanks, higher education, and transportation sectors across the U.S. and Europe.

- Advertisement -

The threat actors use compromised email addresses tied to government and military organizations to initiate trusted communications. They build rapport by referencing the targets’ professional expertise and arrange fictitious meetings or interviews. In these interactions, victims receive links to documents hosted on a Cloudflare Worker URL that mimics the sender’s Microsoft OneDrive account. Victims are instructed to copy a provided device code and press “Next” to access these supposed documents.

Entering the code redirects victims to the legitimate Microsoft device code login portal. Once the code is entered, Microsoft generates an access token, enabling the threat actors to seize control of the victim’s account. Proofpoint tracks this campaign under UNK_AcademicFlare, attributing it to Russia-aligned actors due to its focus on Russia-oriented specialists, Ukrainian governmental, and energy organizations. The method has been previously documented by Microsoft and Volexity as a known tactic among Russian groups such as Storm-2372 and APT29 as detailed here.

Other malicious actors, including the financially motivated e-crime group TA2723, have also employed device code phishing. TA2723 uses salary-related bait in phishing messages to lure victims to fake pages that trigger device code authorization. The surge in these attacks has been facilitated by accessible crimeware tools like the Graphish phishing kit and red-team frameworks such as SquarePhish. Proofpoint states, “the tool is designed to be user-friendly and does not require advanced technical expertise, lowering the barrier for entry and enabling even low-skilled threat actors to conduct sophisticated phishing campaigns.”

Device code authentication is a process where a user enters a code on a trusted device to grant an application access without entering their password directly. Attackers misuse this flow to fraudulently acquire tokens that allow account takeover.

- Advertisement -

To mitigate these risks, it is recommended to enforce Conditional Access policies that block device code authentication flows globally or apply allow-lists restricting device code usage to specific users, devices, or network ranges.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Silver’s rally reignites debate: Bitcoin vs. precious metals

Silver reached a record spot price near $94 per ounce on Monday.Gold climbed to...

Satoshi-era 909 BTC wallet wakes after 13 years, moves $85M.

A Satoshi‑era wallet transferred its full balance of 909.38 BTC—about $84.6 million—after 13 years...

Cardano Volatility Fuels Comeback Hopes After Hoskinson Buzz

Cardano (ADA) trades at $0.36, up 2% in the last 24 hours, after sharp...

Ethereum Leads Bitcoin Liquidations as Macro Headwinds Bite.

Ethereum led crypto liquidations over the last 24 hours, surpassing Bitcoin.Total crypto liquidations totaled...

Bitcoin Falls Amid US-EU Tariff Fears, Drops Near $92K today

Bitcoin traded near $92,000 on Jan. 19 after a weekend decline tied to concerns...
- Advertisement -

Must Read

The Best Bitcoin Casinos of 2025: An Expert’s Data-Driven Guide

Key TakeawaysA Deep Dive into the Top Bitcoin Casinos of 2025Bitcoin Casino Comparison Table1. Stake.com: Best for Variety & Integrated Sports Betting2. BC.Game: Best...
Bitcoin (BTC) $ 90,870.00 2.26%
Ethereum (ETH) $ 3,093.00 3.62%
XRP (XRP) $ 1.93 2.41%
Bittensor (TAO) $ 241.03 3.83%
Polkadot (DOT) $ 1.99 0.06%
Cardano (ADA) $ 0.358721 2.84%
Chainlink (LINK) $ 12.53 1.97%
Hyperliquid (HYPE) $ 23.11 3.94%
Monero (XMR) $ 587.97 8.59%
Hedera (HBAR) $ 0.107128 2.19%
Toncoin (TON) $ 1.56 3.73%