HIGHApt
Verified
Europe / NATO
APT29 OAuth Consent Phishing Campaign Targets 14 NATO Governments
Thursday, March 26, 2026 at 10:00 AM UTC·Source: Microsoft Threat Intelligence
Updated: Friday, March 27, 2026 at 08:00 AM UTC
Executive Summary
APT29 compromises 500+ government accounts across NATO via malicious Azure app registrations requesting mail and file access.
Analysis
APT29 registers malicious Azure apps requesting mail.read and files.read permissions. Targets receive phishing from compromised legitimate government accounts. Once consent granted, persistent access without needing the password. Microsoft has revoked malicious apps and published IOCs.
Timeline
Discovered
Mar 18, 2026
Exploitation Detected
Mar 18, 2026
Published
Mar 26, 2026