Russian GRU's 'Authentic Antics' Malware Hijacks Microsoft 365 Credentials in Stealthy Espionage Campaign
The UK National Cyber Security Centre has exposed APT28, a Russian GRU-linked group, for deploying sophisticated 'Authentic Antics' malware to steal Microsoft 365 credentials and OAuth tokens. This tool operates invisibly within Outlook, using legitimate services to exfiltrate data and evade detection for prolonged espionage. Sanctions against GRU units underscore the escalating threat to cloud-based enterprise security.