logo

Storm-2372 conducts device code phishing campaign

ID: 5c672a6c-6ccd-57aa-881c-30d1d009c4dd

STIX ID: report--5c672a6c-6ccd-57aa-881c-30d1d009c4dd

Feed Name: Microsoft Security

Threat Score
90/100

Date Published: 2025-02-14

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

**Executive summary:** Microsoft Threat Intelligence reports that Storm-2372, a suspected Russia-aligned actor, has conducted a device-code phishing campaign since August 2024 targeting governments, NGOs, and multiple industries across regions; the campaign tricks users into entering device codes to capture access and refresh tokens, abuses Microsoft Graph for email exfiltration and lateral phishing, and recently shifted to using the Microsoft Authentication Broker client ID to register devices and obtain Primary Refresh Tokens (PRTs) for persistent access — Microsoft provides detections, hunting queries, and mitigation guidance including blocking device-code flow, revoking refresh tokens, conditional access, and enrollment restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.