Storm-2372 is a Russia-aligned threat cluster tracked by Microsoft and assessed with moderate confidence to operate in support of Russian interests. The activity has been observed since at least August 2024 and is associated with initial-access operations centered on abuse of Microsoft Entra ID device code authentication. Storm-2372 is closely linked in reporting to Midnight Blizzard tradecraft and has been referenced alongside related Russian clusters and labels including APT29, UTA0304, UTA0307, and UNK_AcademicFlare in discussions of similar device-code phishing activity. The group is known for device code phishing campaigns that use social engineering themed around messaging and collaboration platforms, including Microsoft Teams, Signal, and WhatsApp-style interactions. Victims are lured into entering attacker-generated device codes into legitimate Microsoft authentication pages, allowing the actor to obtain valid access and refresh tokens without stealing passwords directly. Reported targeting includes governments, non-governmental organizations, defense organizations, higher education, telecommunications, healthcare, information technology, and energy sectors across Europe, North America, Africa, and the Middle East. Post-compromise, Storm-2372 has used Microsoft Graph for mailbox access, keyword searching, and email exfiltration. The actor has also leveraged compromised accounts to send additional phishing messages internally, enabling follow-on compromise and lateral expansion. Reporting further indicates use of social engineering delivered through commercial messaging applications and regionally appropriate proxy infrastructure to reduce detection. By February 2025, Storm-2372 had evolved its tradecraft to use the Microsoft Authentication Broker client in the device code flow to obtain refresh tokens that could be used for downstream device registration. This enabled registration of attacker-controlled devices in Entra ID and acquisition of Primary Refresh Tokens, supporting more persistent cloud access and continued collection from organizational resources. The actor’s operations reflect an espionage-oriented focus on covert access to cloud identities, email, and enterprise data rather than disruptive or extortion-driven outcomes.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a Midnight Blizzard initial access sub-cluster known for device code and OAuth code phishing, Microsoft Graph-based email exfiltration, and related tradecraft similar to Storm-2945.
Previously documented threat cluster associated with device code phishing against Microsoft 365 accounts using fake Microsoft Teams invitations and messaging-themed social engineering to trick victims into entering attacker-generated device codes and thereby grant access tokens.
Previously documented activity cluster associated with Microsoft 365 device code phishing using collaboration-themed lures to trick users into authorizing attacker sessions.
Conducts device code phishing campaigns abusing OAuth device authorization flow to obtain valid access tokens and refresh tokens from victims after they complete authentication on legitimate pages.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.