Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Space smoothies fight astronaut muscle loss
    • Why your funding announcement is not the PR win you think it is – and why speaking at events is
    • xAI Asks Court to Strip Alleged Grok Deepfake Nudes Victims of Anonymity
    • Strava Members: Run a 5K Wednesday, Get a Runna Subscription Free
    • I Spent May Evaluating Different Engines for OCR
    • Extra-wide tiny house combines premium finishes with spacious design
    • Property investment startup Dashdot in liquidation, with Budget as ‘the straw that broke the camel’s back’
    • This Is How Trump Finally Signed the AI Executive Order
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Wednesday, June 3
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»What is device code phishing, and why are Russian spies so successful at it?
    News

    What is device code phishing, and why are Russian spies so successful at it?

    Editor Times FeaturedBy Editor Times FeaturedFebruary 16, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    Researchers have uncovered a sustained and ongoing marketing campaign by Russian spies that makes use of a intelligent phishing method to hijack Microsoft 365 accounts belonging to a variety of targets, researchers warned.

    The method is named system code phishing. It exploits “system code movement,” a type of authentication formalized within the industry-wide OAuth standard. Authentication by system code movement is designed for logging printers, good TVs, and comparable gadgets into accounts. These gadgets sometimes don’t assist browsers, making it tough to register utilizing extra customary types of authentication, corresponding to coming into consumer names, passwords, and two-factor mechanisms.

    Reasonably than authenticating the consumer immediately, the input-constrained system shows an alphabetic or alphanumeric system code together with a hyperlink related to the consumer account. The consumer opens the hyperlink on a pc or different system that’s simpler to register with and enters the code. The distant server then sends a token to the input-constrained system that logs it into the account.

    System authorization depends on two paths: one from an app or code working on the input-constrained system in search of permission to log in and the opposite from the browser of the system the consumer usually makes use of for signing in.

    A concerted effort

    Advisories from each safety agency Volexity and Microsoft are warning that risk actors engaged on behalf of the Russian authorities have been abusing this movement since at the least final August to take over Microsoft 365 accounts. The risk actors masquerade as trusted, high-ranking officers and provoke conversations with a focused consumer on a messenger app corresponding to Sign, WhatsApp, and Microsoft Groups. Organizations impersonated embody:



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    Indian IT companies have spent $7.1B on acquisitions since the start of 2025 to gain clients, as AI-led pricing pressure weakens organic growth (Shristi Achar/The Economic Times)

    June 3, 2026

    People Incorporated launches $18B bid for MGM Resorts

    June 3, 2026

    Illinois prediction markets face new transaction tax

    June 3, 2026

    Galveston gambling investigation expands with coordinated raids

    June 2, 2026

    Microsoft announces the Agent Control Specification, an open-source standard that aims to provide granular, consistent governance over AI agent behavior (Ram Iyer/TechCrunch)

    June 2, 2026

    Dozens of Red Hat packages backdoored through its official NPM channel

    June 2, 2026

    Comments are closed.

    Editors Picks

    Space smoothies fight astronaut muscle loss

    June 3, 2026

    Why your funding announcement is not the PR win you think it is – and why speaking at events is

    June 3, 2026

    xAI Asks Court to Strip Alleged Grok Deepfake Nudes Victims of Anonymity

    June 3, 2026

    Strava Members: Run a 5K Wednesday, Get a Runna Subscription Free

    June 3, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Today’s NYT Connections Hints, Answers for Dec. 8 #911

    December 7, 2025

    FDA approves first blood test for early Alzheimer’s detection

    May 20, 2025

    The foundation for a governed agent workforce: DataRobot and NVIDIA RTX PRO 4500

    March 16, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.