Storm-2372 is a Russia-aligned cyberespionage threat cluster active since at least August 2024 and assessed as an initial-access operations sub-cluster associated with Midnight Blizzard. It has targeted organizations of strategic intelligence interest, including government, defense, energy, health care, telecommunications, information technology, higher-education, and non-governmental organizations across North America, Europe, Africa, and the Middle East. Storm-2372 is notable for spear-phishing and social-engineering campaigns that abuse Microsoft Entra ID OAuth device-code and OAuth authorization flows. Its lures have impersonated collaboration and messaging services, including Microsoft Teams, to induce targets to enter attacker-provided device codes on legitimate Microsoft authentication pages. This technique yields valid access and refresh tokens following victim sign-in and MFA completion, enabling account takeover without collecting a password. Observed post-compromise activity includes Microsoft Graph-based email collection and exfiltration, use of Microsoft Authentication Broker token requests, and attacker-controlled Entra device registration to obtain Primary Refresh Tokens and maintain access. Its device-code phishing tradecraft has subsequently been adopted and commercialized by criminal phishing frameworks, but technical similarity alone does not establish Storm-2372 attribution for those later operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a comparison point for GhostCode’s post-compromise objectives; it is not attributed to the campaign described in this reference.
Mène des campagnes d'espionnage contre des cibles de renseignement stratégique en combinant des liens de spear-phishing avec le device code phishing afin d'obtenir des jetons OAuth.
Early adopter of device code phishing in a major campaign, compromising organizations across multiple industries and regions.
Related activity cluster mentioned for technical overlaps with Storm-2945, particularly device code phishing and exfiltration via Microsoft Graph.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.