Microsoft Disrupts Russian Cyber Operation Against NATO Countries

The Microsoft Threat Intelligence Center (MSTIC) has disrupted the activities of a Russian-linked threat actor targeting people and organizations in NATO countries.

Identified as SEABORGIUM by Microsoft, by Google as ColdRiver, and by Proofpoint as TA446, the campaign seeks to steal sensitive emails from organizations and individuals of interest to Russia.

Microsoft was able to disrupt SEABORGIUM’s campaigns by disabling accounts used for monitoring, phishing and email collection.

In order to carry out attacks, SEABORGIUM creates online personas via email, social media and LinkedIn accounts that are used in social engineering campaigns. These fake personas are then used to target victims.

Using the fake persona, the attackers build a relationship with the victims, which ultimately leads to the attackers sending a phishing attachment.

According to Microsoft, these malicious attachments are spread via emails with attached PDFs, links to file hosting services, or OneDrive accounts hosting the PDF documents.

After accessing a targeted email account, Microsoft claims that they either steal emails and attachments, or set forwarding rules to receive all new emails sent to the compromised account.

To protect against this type of attack, defenses should disable automatic email forwarding in Microsoft 365, use IOCs to investigate potential compromises, require MFA for all accounts, and require FIDO security keys for greater security.

The sources for this piece include an article in BleepingComputer.

Top Stories

Related Articles

May 12, 2026 Θα έχετε την καλύτερη εντύπωση για το Wildsino αν παίξετε αυτά τα παιχνίδια στο tablet σας ή σε more...

May 12, 2026 Te softwarematige kansspelen zorgt gij ontwikkelaar pro diegene gij RTP klopt, gezag narekenen of de achterliggende algoritmen wa more...

May 11, 2026 Most other intimate source, such as other kid, Disregard Holtz, affirmed he could be “ 11may however fighting more...

May 11, 2026 Government said Monday he's investigating the fresh disappearance from Nancy Guthrie, mom from "Today" host Savannah Guthrie, as more...

Jim Love

Jim Is and author and pud cast host with over 40 years in technology.