Target Industry

Storm-2372 primarily targets a wide range of sectors, including government, non-governmental organisations (NGOs), IT services and technology, defence, telecommunications, health, higher education, and energy. 

Overview

A new phishing campaign leveraged by Storm-2372 has been identified by Microsoft Threat Intelligence. It’s a sophisticated threat that poses a significant risk to Microsoft 365 security because it targets Microsoft 365 accounts using a technique called device code phishing. This method involves tricking victims into providing authentication codes, which the attackers then use to gain access to their accounts. 

Impact

This tactic enables threat actors to access sensitive information, such as emails and cloud data, by deceiving victims into revealing their authentication codes. The threat actors can maintain access to compromised accounts for extended periods. 

Additionally, they can move laterally within compromised networks, increasing the risk of further account compromises and data loss. Organisations may face disruptions as they work to identify and mitigate the impact of these attacks, affecting productivity and service delivery. 

Exploitation

Storm-2372 exploits Microsoft Teams meeting invites through a technique called device code phishing. This exploits the OAuth 2.0 Device Authorisation Grant flow, which is designed for devices with limited input capabilities. By persuading victims to provide their authentication codes, the threat actor can gain and maintain access to the victim’s accounts and sensitive information. 

Storm-2372 initiates the campaign with social engineering to establish a connection with the victim via messaging platforms like WhatsApp, Signal, and Microsoft Teams. Once the threat actor has gained the trust of the victim, a phishing email is sent with an invite to a Microsoft Teams meeting. These emails appear to be legitimate Microsoft Teams meeting invitations.  

When the victim clicks on the invitation, they are prompted to authenticate using a device code on a legitimate Microsoft login page. The threat actors persuade the victim to enter the device code, generating an authentication token that the attackers then capture. With this token, the threat actors can further exploit the compromised account by sending phishing messages to colleagues. This method enables them to move laterally within compromised networks, leading to potential data loss. 

Containment, Mitigations & Remediations

To mitigate the risks posed by Storm-2372’s device code phishing campaign, the following measures can be implemented: 

  • Restrict Device Code Flow: Block it wherever possible, only allow device code flow where it is absolutely necessary in order to reduce the attack surface 
  • Revoke Tokens: If you suspect any device code phishing activity, immediately revoke the user’s refresh tokens by calling revokeSignInSessions 
  • Sign-In Risk Policy: Implement a sign-in risk policy to automate responses to risky sign-ins 
  • Multi-Factor Authentication (MFA): Enforce MFA for all users to add an extra layer of security.  

Indicators of Compromise

Some Indicators of Compromise for this type of phishing campaign can be: 

  • Phishing Emails: Emails that masquerade as Microsoft Teams meeting invitations, prompting users to authenticate using a device code 
  • Unusual Login Locations: Login attempts from unexpected geographical locations 
  • Multiple Failed Login Attempts: Repeated failed sign-ins, indicating attempts to access accounts using stolen credentials 
  • Unexpected Outbound Network Traffic: Unusual patterns in data leaving the network 
  • Changes in Account Behaviour: Anomalies in user account activity, such as accessing unusual files or services 
  • New Software Installations: Unplanned installations or updates, potentially indicating malicious software. 

Threat Landscape

More than 3.7 million companies worldwide rely on Microsoft 365 products. Microsoft has detected an increase in cyber-attack campaigns that exploit legitimate file hosting services. Due to Storm-2372’s complexity, this threat is concerning because of its advanced capabilities and widespread use. 

Threat Group Attribution

Emerging in August 2024, Storm-2372 (DEV-0586) is a cyber threat group linked to Russia. It has been conducting sophisticated phishing campaigns, particularly using a technique called device code phishing. Its targets include various sectors such as government, NGOs, IT services, defence, telecommunications, health, education, and energy across Europe, North America, Africa, and the Middle East. 

TTPs

  • T1071.001: Application Layer Protocol: Web Protocols 
  • T1071.003: Application Layer Protocol: Mail Protocols 
  • T1556.004: Modify Authentication Process: Device Code Phishing 

Further Information

https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/?msockid=3afc6f9bb217647c11d77aeeb34f655f 

https://www.techradar.com/pro/security/russian-cyberattackers-spotted-hitting-microsoft-teams-with-new-phishing-campaign 

https://www.infosecurity-magazine.com/news/russian-microsoft-device-code/ 

Intelligence Terminology Yardstick

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content