Threadlinqs IntelligenceStart free

Threat actorTracked since 2026-04

UTA0307

As of 2026-09-27, UTA0307 is a threat actor tracked by Threadlinqs Intelligence across 3 threats spanning phishing. ATT&CK coverage spans 66 techniques across 13 tactics in 3 of 3 tracked threats. Most-observed techniques: T1528 (Steal Application Access Token), T1566 (Phishing), T1583 (Acquire Infrastructure).

Tracked threats
33 high
First seen
2026-04-06
Last seen
2026-06-20
ATT&CK techniques
66across 3 of 3 threats
Related CVEs
0None referenced
3 tracked threat(s) · Categories: PHISHING

Activity timeline

UTA0307 appears in 3 tracked threats between and ; the busiest month was 2026-06 with 2 reports.

ATT&CK techniques observed

66 techniques observed across 3 of 3 tracked threats · Resource Development (10), Stealth (formerly Defense Evasion) (8), Persistence (7), Credential Access (6), Initial Access (6), Reconnaissance (6)
  • T1528 Steal Application Access Token — Credential Accessobserved in 3 of 3 tracked threats
  • T1566 Phishing — Initial Accessobserved in 3 of 3 tracked threats
  • T1583 Acquire Infrastructure — Resource Developmentobserved in 3 of 3 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 3 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 2 of 3 tracked threats
  • T1078 Valid Accounts — Persistenceobserved in 2 of 3 tracked threats
  • T1087 Account Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1098 Account Manipulation — Persistenceobserved in 2 of 3 tracked threats
  • T1102 Web Service — Command and Controlobserved in 2 of 3 tracked threats
  • T1114 Email Collection — Collectionobserved in 2 of 3 tracked threats
  • T1187 Forced Authentication — Credential Accessobserved in 2 of 3 tracked threats
  • T1204 User Execution — Executionobserved in 2 of 3 tracked threats
  • T1526 Cloud Service Discovery — Discoveryobserved in 2 of 3 tracked threats
  • T1550 Use Alternate Authentication Material — Lateral Movementobserved in 2 of 3 tracked threats
  • T1567 Exfiltration Over Web Service — Exfiltrationobserved in 2 of 3 tracked threats

Tracked threats