Storm-2372 conducts device code phishing campaign


Microsoft discovered cyberattacks being launched by a group they call Storm-2372, who they assess with medium confidence aligns with Russia’s interests and tradecraft.

The attacks appear to have been ongoing since August 2024 and have targeted governments, NGOs, and a wide range of industries in multiple regions. The attacks use a specific phishing technique called “device code phishing” that tricks users to log into productivity apps while Storm-2372 actors capture the information from the log in (tokens) that they can use to then access compromised accounts.

Read more…
Source: Microsoft


Sign up for our Newsletter


Related:

  • Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

    July 23, 2026

    A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking), primarily as ...

  • Experts warn hackers could shut down entire power grids by hijacking cloud accounts

    July 21, 2026

    Whenever an AI data center thinks really, really hard, it can increase its power consumption so much to trigger disruptions and possibly even blackouts and gear malfunctions. So, is it possible for a malicious actor to trigger this scenario deliberately, in order to cause physical harm? Multiple researchers from the Zhejiang University in Hangzhou, China, wrote ...

  • Inside an Exposed WebDAV Malware Delivery Lab

    July 20, 2026

    An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery paths, social engineering lures, and WebDAV execution methods. Our analysis reveals an ...

  • FBI Warns of Scammers Impersonating the IC3

    July 20, 2026

    This Public Service Announcement contains updated information about an ongoing fraud scheme where criminal scammers are impersonating FBI personnel facilitating Internet Crime Complaint Center (IC3) complaints to deceive and revictimize individuals. This scheme combines several exploitation tactics to include the targeting of previous victims, the use of artificial intelligence (AI)-generated videos to create fictitious or misleading promotional ...

  • Hugging Face confirms breach affected internal datasets and credentials

    July 20, 2026

    Hugging Face, a platform that hosts AI models and datasets, said its internal datasets and service credentials were compromised in a hack last week. The company disclosed the breach on Friday, but said it was still investigating whether any customer or partner data was stolen during the incident. In a blog post, the company said a dataset uploaded ...

  • Ernst & Young reveals data breach following hack on support system

    July 20, 2026

    Ernst & Young (EY) has confirmed suffering a cyberattack in which it lost sensitive customer information, including tax data. In a data breach notification letter sent to affected individuals, the firm said that on April 23, 2026, it spotted “anomalous activity” within a third-party platform its IT team uses. This is an IT service management platform ...