Storm-2372 is a suspected Russian-aligned nation-state actor known for messaging phishing and device code authentication abuse.
Analyst brief
Storm-2372 is a suspected nation-state actor aligned with Russian interests. It targets governments, NGOs, and various industries across Europe, North America, Africa, and the Middle East. Its primary TTPs include impersonating prominent individuals on messaging services like WhatsApp and Signal to build rapport, then sending phishing invitations that trick users into completing device code authentication requests for initial access and Graph API data harvesting, including email collection. Defenders should monitor for anomalous authentication requests, enforce strict controls on device code flow, and educate users about unexpected messaging invitations, especially from impersonated figures.
Storm-2372
unknown
Storm-2372 is a suspected nation-state actor aligned with Russian interests, engaging in device code phishing campaigns targeting governments, NGOs, and various industries across Europe, North America, Africa, and the Middle East. The actor employs tactics that involve impersonating prominent individuals through third-party messaging services like WhatsApp and Signal to gain rapport before sending phishing invitations. These invitations lure users into completing device code authentication requests, granting Storm-2372 initial access to victim accounts and enabling Graph API data collection activities, including email harvesting. Microsoft has observed the actor utilizing keyword searches within compromised accounts to exfiltrate sensitive information.
What authentication method does Storm-2372 use to gain initial access?+
Storm-2372 uses device code authentication requests, tricking victims into completing these requests through phishing invitations to gain initial access.
What key sectors are targeted by Storm-2372?+
Storm-2372 targets governments, NGOs, and various industries across Europe, North America, Africa, and the Middle East.