logo

Storm-2372 used the device code phishing technique since August 2024

ID: 8fea5cb4-bafc-5fec-9fdd-95a0a4370f7d

STIX ID: report--8fea5cb4-bafc-5fec-9fdd-95a0a4370f7d

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2025-02-16

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Microsoft Threat Intelligence attributes a device-code phishing campaign to Storm-2372 (likely Russia-aligned) active since August 2024, targeting governments, NGOs, and multiple industries across regions. The actor lures victims with messaging-app-like invites (e.g., fake Teams), tricks them into entering attacker-generated device codes on legitimate sign-in pages, captures access and refresh tokens, and uses those tokens to access mail and cloud data and move laterally; Microsoft observed shifts in client IDs and proxy use. Recommended mitigations include blocking device code flow, enforcing MFA, and applying least privilege.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.