Product
high
threat
Russian-Linked Clusters Abuse Authentication Flows for Targeted Credential Theft
3 TTPs 1 IOCSuspected Russian threat clusters UNC6293 and UNC7005 are abusing legitimate OAuth, app password, and device code authentication workflows to bypass MFA and compromise high-value targets in academia, government, and defense.
Microsoft Account +1
ICE RELIC
phishing
credential-theft
oauth
espionage
ice-relic
3t
1i
high
advisory
Sophisticated AitM Phishing Campaign Targeting US Organizations
2 rules 2 TTPsA sophisticated phishing campaign targeting US organizations uses a 'code of conduct review' theme to lure victims to a malicious website, employing adversary-in-the-middle (AitM) techniques to capture authentication tokens and gain account access.
Microsoft account +1
phishing
aitm
credential-access
initial-access
2r
2t