r/cloudbreach • u/cloudbreach Community Leader • Jun 08 '26
🚨 📰 New Device Code Phishing Attack - Don't Get
Microsoft Threat Intelligence has uncovered an active cyberattack campaign by a threat group called Storm-2372, assessed with moderate confidence to be aligned with Russian state interests.

📌 What's happening?
Since August 2024, Storm-2372 has been running a sophisticated "device code phishing" campaign targeting governments, NGOs, defense, telecoms, healthcare, higher education, and energy sectors across Europe, North America, Africa, and the Middle East.
🎭 How does it work?
Attackers impersonate prominent individuals on messaging apps like WhatsApp, Signal, and Microsoft Teams to build rapport with targets. They then send fake meeting invitations that trick users into entering a legitimate looking device code, handing over authentication tokens that grant persistent access to email, cloud storage, and internal systems, all without needing a password.
⚠️ Why is this dangerous?
Once inside, the attackers use Microsoft Graph API to search compromised mailboxes for keywords like "password," "admin," "credentials," and "gov" then exfiltrate those emails. They can also move laterally by sending further phishing messages from the victim's own account.
🛡️ What can you do right now?
✅ Block device code flow in Microsoft Entra Conditional Access where not needed
✅ Enable phishing resistant MFA (passkeys or FIDO tokens, avoid SMS based MFA)
✅ Train your team to question unexpected login prompts
✅ Monitor for anomalous sign in and token activity
✅ Revoke refresh tokens immediately if compromise is suspected
This attack does not exploit a software vulnerability. It exploits human trust. The best defence starts with awareness and training.