UTA0304
UTA0304 is a Russia-aligned threat cluster that has been attributed to device code phishing activity targeting Microsoft 365 accounts. Reporting cited in the source material links UTA0304 alongside Storm-2372, APT29, UTA0307, and UNK_AcademicFlare to abuse of Microsoft OAuth device authorization flows. In these operations, victims are lured to the legitimate Microsoft device login page and instructed to enter attacker-supplied device codes, allowing the threat actor to obtain access and refresh tokens for account takeover; the resulting access can persist even after password resets. Device code phishing associated with Russia-aligned clusters was documented by Microsoft and Volexity in February 2025, with subsequent reporting noting continued use of the technique. The broader activity described in the source material targeted Microsoft 365 identities across sectors including government, think tanks, higher education, transportation, construction, non-profits, real estate, manufacturing, financial services, healthcare, legal, and government, including organizations in the U.S., Canada, Australia, New Zealand, Germany, and Europe, as well as individuals and organizations connected to Ukraine and human rights. Volexity also noted that related Microsoft 365 social-engineering activity could be connected to APT29, UTA0304, and UTA0307, but did not rule out that relationship. Known alias directly provided in the content: uta0304.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Capital Goods
- Financial Services
- Health Care Equipment & Services
- Commercial & Professional Services
- Software & Services
- Real Estate Management & Development
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
- 🇨🇦 Canada
- 🇦🇺 Australia
- 🇳🇿 New Zealand
- 🇩🇪 Germany
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attributed as a Russia-aligned activity cluster involved in device code phishing campaigns against Microsoft 365 users.
UTA0304 is a Russia-aligned threat actor cluster using device code phishing to compromise Microsoft 365 accounts.
Referenced only as a potentially related threat cluster; no distinct TTPs or operations are attributed to UTA0304 in the provided content.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.