Distinct Russian clusters have been conducting phishing activity focused on Application Specific Passwords (ASP), OAuth flows, and malware delivery. All of these operations seem focused on account compromise.
This piece follows up on and expands upon our blog from last year on UNC6293’s ASP phishing to show these threat actors’ evolution, highlighting these additional TTPs.