If you dread a Microsoft Teams invite, just wait until it turns out to be a Russian phish
ID: f50862bb-49a7-5c42-99aa-a9a61c261d20
STIX ID: report--f50862bb-49a7-5c42-99aa-a9a61c261d20
Feed Name: The Register (Security)
Microsoft reports that Storm-2372, a suspected Russia-aligned APT, has been conducting an active device-code phishing campaign since August that uses forged Microsoft Teams invites and social engineering to trick targets into entering device verification codes; attackers then exchange those codes for access tokens to access email and cloud data, search mailboxes via Microsoft Graph for credential-related information, and propagate within organizations by sending further phishing messages from compromised accounts. Microsoft recommends limiting device code flow usage, revoking refresh tokens for suspected accounts, and enforcing conditional access to force re-authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
