Storm-2372 conducts device code phishing campaign
ID: 5c672a6c-6ccd-57aa-881c-30d1d009c4dd
STIX ID: report--5c672a6c-6ccd-57aa-881c-30d1d009c4dd
Feed Name: Microsoft Security
**Executive summary:** Microsoft Threat Intelligence reports that Storm-2372, a suspected Russia-aligned actor, has conducted a device-code phishing campaign since August 2024 targeting governments, NGOs, and multiple industries across regions; the campaign tricks users into entering device codes to capture access and refresh tokens, abuses Microsoft Graph for email exfiltration and lateral phishing, and recently shifted to using the Microsoft Authentication Broker client ID to register devices and obtain Primary Refresh Tokens (PRTs) for persistent access — Microsoft provides detections, hunting queries, and mitigation guidance including blocking device-code flow, revoking refresh tokens, conditional access, and enrollment restrictions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
