Also known as: tracked as, broader Midnight Blizzard operations, APT29, like TeamsPhisher, to distribute DarkGate malware, Midnight Blizzard
Storm-2372 is a suspected nation-state actor aligned with Russian interests, engaging in device code phishing campaigns targeting governments, NGOs, and various industries across Europe, North America, Africa, and the Middle East. The actor employs tactics that involve impersonating prominent individuals through third-party messaging services like WhatsApp and Signal to gain rapport before sending phishing invitations. These invitations lure users into completing device code authentication requests, granting Storm-2372 initial access to victim accounts and enabling Graph API data collection activities, including email harvesting. Microsoft has observed the actor utilizing keyword searches within compromised accounts to exfiltrate sensitive information.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Storm‑2372 is a Russian‑aligned threat actor that launched large‑scale device code phishing campaigns in 2024, targeting governments, NGOs and critical infrastructure across Europe, North America and the Middle East. The actors steal OAuth credentials through lures that mimic popular messaging apps, enabling persistent access to Microsoft 365 accounts via Graph API harvesting and encrypted token reuse. Their operations combine credential theft with remote‑desktop abuse and malicious cloud‐hosting services such as Railway.com. enhanced_description":"Storm‑2372 appears to be a nation‑state actor (potentially linked to APT29 or Midnight Blizzard) focused on financial gain and information gathering across numerous high-value sectors, including defense, energy, healthcare and finance. The group’s key method is device code phishing against Microsoft Entra ID: by impersonating prominent individuals through WhatsApp, Signal or Microsoft Teams meetings, they coerce victims into completing the OAuth device‑code flow on legitimate login.microsoftonline.com pages while hidden in a separate token‑harvesting domain such as Railway.com. Captured access tokens allow attackers to acquire Primary Refresh Tokens (PRT), granting them long‑term persistence without triggering MFA. They then register attacker‑controlled devices via the Microsoft Authentication Broker, expand MFA coverage by enrolling bogus devices, and execute further credential‑access tactics through remote‑desktop tools like AnyDesk. The group also leverages multi‑hop redirect chains with clean IP reputations to evade detection, exploiting third‑party cloud services as command‑and‑control channels. The campaign demonstrates a sophisticated blend of social engineering, Microsoft identity platform exploitation and stealthy persistence mechanisms, enabling large‑scale data exfiltration via Graph API harvesting of emails, documents, and other privileged data."
No campaigns linked yet.
No observed data linked yet.
13
Techniques
41
Tools
0
Campaigns
43
IOCs
0
Observed Data
2
Tactics