Storm-2372 is a Microsoft-tracked threat actor assessed with moderate confidence to be aligned with Russian interests. Microsoft reported the group has been active since at least August 2024. The actor has targeted governments, NGOs, and organizations in sectors including IT services/technology, defense, telecommunications, health, higher education, and energy/oil and gas across Europe, North America, Africa, and the Middle East. Storm-2372 is primarily associated with device code phishing against Microsoft 365 and Entra ID environments. The group uses social-engineering lures themed around messaging and collaboration platforms, including fake Microsoft Teams meeting invitations and lures resembling WhatsApp, Signal, and Teams interactions, to trick victims into entering attacker-generated device codes into Microsoft’s legitimate device login flow. This abuse yields valid access and refresh tokens and enables account takeover and persistent access without exploiting a Microsoft vulnerability. Microsoft observed Storm-2372 using Microsoft Graph for post-compromise activity, including searching compromised mailboxes with terms such as "username," "password," "admin," "teamviewer," "anydesk," "credentials," "secret," "ministry," and "gov," exfiltrating email, and sending additional device-code phishing messages from compromised internal accounts for lateral movement. Microsoft also reported that, by February 14, 2025, the actor had shifted to using the Microsoft Authentication Broker client ID to obtain refresh tokens that supported downstream device registration in Entra ID and subsequent access via Primary Refresh Tokens (PRTs). Microsoft observed the actor registering attacker-controlled devices and using regionally appropriate proxies to reduce detection. The content also references Storm-2372 alongside other Russia-aligned clusters associated with device code phishing, including APT29, UTA0304, and UTA0307.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously documented threat cluster associated with device code phishing against Microsoft 365 accounts using fake Microsoft Teams invitations and messaging-themed social engineering to trick victims into entering attacker-generated device codes and thereby grant access tokens.
Previously documented activity cluster associated with Microsoft 365 device code phishing using collaboration-themed lures to trick users into authorizing attacker sessions.
Conducts device code phishing campaigns abusing OAuth device authorization flow to obtain valid access tokens and refresh tokens from victims after they complete authentication on legitimate pages.
Referenced as a comparison point for similar token abuse tactics, specifically use of Microsoft Authentication Broker client ID to obtain refresh tokens supporting downstream device registration and email access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.