Storm-2372 Cyber Threat: Advanced Phishing Tactics Targeting Multiple Sectors

Article Highlights
Off On

The emergence of a cyber-attack threat cluster known as Storm-2372 has raised significant concerns across various sectors. Identified by Microsoft, this threat has been active since August 2024, targeting organizations in government, NGOs, IT services, technology, defense, telecommunications, health, higher education, and energy/oil and gas sectors. The attacks have spanned Europe, North America, Africa, and the Middle East, showcasing a broad and alarming reach.

The Rise of Storm-2372

Novel Phishing Techniques

Storm-2372 has introduced a novel phishing technique called ‘device code phishing.’ This method involves tricking victims into logging into productivity applications to capture authentication tokens. These tokens allow unauthorized access to compromised accounts, bypassing the need for passwords. The attackers have skillfully leveraged legitimate messaging platforms such as WhatsApp, Signal, and Microsoft Teams to pose as prominent individuals, enhancing their credibility and increasing the likelihood of a successful attack.

Social Engineering Tactics

One of the most insidious aspects of these attacks is the use of social engineering. By sending what appear to be legitimate Microsoft Teams meeting invitations, the threat actors lure victims into entering a device code on a legitimate sign-in page. This tactic capitalizes on the victim’s assumptions of authenticity and trust in commonly used tools. Once an authentication token is captured, the attackers exploit it to gain entry to the victim’s accounts, providing unauthorized access to sensitive data.

Exploiting Authentication Tokens

Persistent Access and Privilege Escalation

Once an account is compromised, the attackers can maintain access as long as the tokens remain valid. This extended access allows them to potentially escalate their privileges within the network, gaining more control over the compromised systems. Microsoft’s observations indicate that the attackers use the Microsoft Graph service to conduct keyword searches through the compromised account’s messages.

Mitigation Strategies

To mitigate this risk, Microsoft suggests several measures: blocking device code flow where feasible, enabling phishing-resistant multi-factor authentication (MFA), and adhering to the principle of least privilege. Blocking device code flow can directly counteract the tactic used by Storm-2372, making it harder for the attackers to obtain valid tokens. Enabling phishing-resistant MFA adds an additional layer of security, requiring multiple forms of verification before granting access and reducing the risk of unauthorized access.

Evolving Tactics of Storm-2372

Shift in Attack Methods

In an update on February 14, 2025, Microsoft highlighted a shift in Storm-2372’s tactics, reflecting the group’s ability and determination to adapt to emerging defenses. The threat actors now employ the specific client ID for the Microsoft Authentication Broker in the device code flow.

Concealing Activities

Additionally, the attackers have been observed to utilize regionally appropriate proxies to better conceal the suspicious nature of their sign-in activities. By mimicking regional sign-in patterns, the attackers can evade detection and appear as legitimate users, making it more challenging for organizations to identify and respond to the threat.

Observations by Volexity

Multiple Russian Threat Actors

Cybersecurity firm Volexity has independently observed at least three distinct Russian threat actors employing the device code phishing method to compromise Microsoft 365 accounts since mid-January 2025. These campaigns have impersonated individuals from established entities, including the United States Department of State, the Ukrainian Ministry of Defence, and the European Union Parliament.

Specific Attack Instances

One particularly active group, UTA0304, initiated contact with a target through the Signal messaging app, posing as an official from the Ukrainian Ministry of Defence. They persuaded the victim to switch to another secure messaging app, Element, then sent a spear-phishing email containing a link to join a chat room.

Strategic Timing and Real-Time Engagement

The strategic timing of the phishing messages is a critical component of the attackers’ methodology. The generated device codes’ short validity window, typically 15 minutes, necessitates swift action from the victim, adding a sense of urgency to the engagement.

Looking Ahead

The rising threat of a cyber-attack cluster known as Storm-2372 has created significant alarm across multiple sectors. This threat, identified by Microsoft, has been active since August 2024 and continues to pose substantial risks. Storm-2372 targets a wide array of organizations, including those in government, non-governmental organizations (NGOs), IT services, technology, defense, telecommunications, health, higher education, and energy/oil and gas sectors. The attacks are not confined to a specific region but have impacted entities across Europe, North America, Africa, and the Middle East, indicating a widespread and concerning reach.

Microsoft’s identification of Storm-2372 underscores the growing sophistication and persistence of cyber threats in today’s digital age. Organizations within the affected sectors must enhance their cybersecurity measures to safeguard against these relentless attacks. This threat cluster’s broad target range and global span highlight the urgent need for heightened vigilance and advanced security protocols to defend critical infrastructures and sensitive information from such pervasive cyber threats.

Explore more

How to Scale B2B Lead Generation on LinkedIn Successfully?

The landscape of professional networking has undergone a radical transformation, moving away from simple connection requests toward a centralized ecosystem for business growth. In the current market, the platform serves as the primary conduit for high-value transactions, where digital presence directly correlates with market share. Organizations that treat this space as a static directory find themselves falling behind competitors who

Ukraine’s E-Commerce Tax Bill Faces Critical Hurdles for EU Integration

The rapid evolution of the digital marketplace has forced governments worldwide to rethink fiscal boundaries, yet Ukraine’s attempt to legislate this boundary through Draft Law No. 15112-d reveals a profound friction between wartime survival and the strict requirements of European integration. As the country navigates its path into the European Union, the Verkhovna Rada faces a daunting task: creating a

Vietnam Strengthens Legal Compliance for E-commerce Growth

Behind the vibrant glow of smartphone screens across Hanoi and Ho Chi Minh City, a massive digital transformation is quietly reshaping the economic identity of the nation through an unprecedented surge in online transactions. This shift represents more than just a change in shopping habits; it signifies a structural evolution where the virtual marketplace is no longer an alternative to

How Agentic AI Is Transforming the B2B Buying Journey

Across the global enterprise landscape, a profound transformation is quietly unfolding as autonomous software agents begin to dominate the intricate process of corporate procurement and vendor selection. This evolution represents a departure from the days when human curiosity drove the early stages of the sales cycle. Today, the initial heavy lifting of market research, technical vetting, and vendor comparison is

10 Best Free or Low-Cost CRM Tools for Small Businesses

Many inexpensive CRM options provide unlimited file storage, making it easier for service-based businesses to manage client contracts and project documents. In the current landscape of 2026, small and midsize enterprises are increasingly moving away from antiquated manual tracking in favor of centralized digital hubs that unify customer interactions. The competitive pressure to deliver personalized experiences has made customer relationship