Target Industry
Storm-2372 primarily targets a wide range of sectors, including government, non-governmental organisations (NGOs), IT services and technology, defence, telecommunications, health, higher education, and energy.
Overview
A new phishing campaign leveraged by Storm-2372 has been identified by Microsoft Threat Intelligence. It’s a sophisticated threat that poses a significant risk to Microsoft 365 security because it targets Microsoft 365 accounts using a technique called device code phishing. This method involves tricking victims into providing authentication codes, which the attackers then use to gain access to their accounts.
Impact
This tactic enables threat actors to access sensitive information, such as emails and cloud data, by deceiving victims into revealing their authentication codes. The threat actors can maintain access to compromised accounts for extended periods.
Additionally, they can move laterally within compromised networks, increasing the risk of further account compromises and data loss. Organisations may face disruptions as they work to identify and mitigate the impact of these attacks, affecting productivity and service delivery.
Exploitation
Storm-2372 exploits Microsoft Teams meeting invites through a technique called device code phishing. This exploits the OAuth 2.0 Device Authorisation Grant flow, which is designed for devices with limited input capabilities. By persuading victims to provide their authentication codes, the threat actor can gain and maintain access to the victim’s accounts and sensitive information.
Storm-2372 initiates the campaign with social engineering to establish a connection with the victim via messaging platforms like WhatsApp, Signal, and Microsoft Teams. Once the threat actor has gained the trust of the victim, a phishing email is sent with an invite to a Microsoft Teams meeting. These emails appear to be legitimate Microsoft Teams meeting invitations.
When the victim clicks on the invitation, they are prompted to authenticate using a device code on a legitimate Microsoft login page. The threat actors persuade the victim to enter the device code, generating an authentication token that the attackers then capture. With this token, the threat actors can further exploit the compromised account by sending phishing messages to colleagues. This method enables them to move laterally within compromised networks, leading to potential data loss.
Containment, Mitigations & Remediations
To mitigate the risks posed by Storm-2372’s device code phishing campaign, the following measures can be implemented:
- Restrict Device Code Flow: Block it wherever possible, only allow device code flow where it is absolutely necessary in order to reduce the attack surface
- Revoke Tokens: If you suspect any device code phishing activity, immediately revoke the user’s refresh tokens by calling revokeSignInSessions
- Sign-In Risk Policy: Implement a sign-in risk policy to automate responses to risky sign-ins
- Multi-Factor Authentication (MFA): Enforce MFA for all users to add an extra layer of security.
Indicators of Compromise
Some Indicators of Compromise for this type of phishing campaign can be:
- Phishing Emails: Emails that masquerade as Microsoft Teams meeting invitations, prompting users to authenticate using a device code
- Unusual Login Locations: Login attempts from unexpected geographical locations
- Multiple Failed Login Attempts: Repeated failed sign-ins, indicating attempts to access accounts using stolen credentials
- Unexpected Outbound Network Traffic: Unusual patterns in data leaving the network
- Changes in Account Behaviour: Anomalies in user account activity, such as accessing unusual files or services
- New Software Installations: Unplanned installations or updates, potentially indicating malicious software.
Threat Landscape
More than 3.7 million companies worldwide rely on Microsoft 365 products. Microsoft has detected an increase in cyber-attack campaigns that exploit legitimate file hosting services. Due to Storm-2372’s complexity, this threat is concerning because of its advanced capabilities and widespread use.
Threat Group Attribution
Emerging in August 2024, Storm-2372 (DEV-0586) is a cyber threat group linked to Russia. It has been conducting sophisticated phishing campaigns, particularly using a technique called device code phishing. Its targets include various sectors such as government, NGOs, IT services, defence, telecommunications, health, education, and energy across Europe, North America, Africa, and the Middle East.
TTPs
- T1566.001: Spearphishing Attachment
- T1566.002: Spearphishing Link
- T1078: Valid Accounts
- T1071.001: Application Layer Protocol: Web Protocols
- T1071.003: Application Layer Protocol: Mail Protocols
- T1071.004: Application Layer Protocol: DNS
- T1556.004: Modify Authentication Process: Device Code Phishing
Further Information
https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/?msockid=3afc6f9bb217647c11d77aeeb34f655f
https://www.infosecurity-magazine.com/news/russian-microsoft-device-code/
Intelligence Terminology Yardstick













