Storm-2372 used the device code phishing technique since August 2024
ID: 8fea5cb4-bafc-5fec-9fdd-95a0a4370f7d
STIX ID: report--8fea5cb4-bafc-5fec-9fdd-95a0a4370f7d
Feed Name: Security Affairs
Microsoft Threat Intelligence attributes a device-code phishing campaign to Storm-2372 (likely Russia-aligned) active since August 2024, targeting governments, NGOs, and multiple industries across regions. The actor lures victims with messaging-app-like invites (e.g., fake Teams), tricks them into entering attacker-generated device codes on legitimate sign-in pages, captures access and refresh tokens, and uses those tokens to access mail and cloud data and move laterally; Microsoft observed shifts in client IDs and proxy use. Recommended mitigations include blocking device code flow, enforcing MFA, and applying least privilege.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
