Storm-2372 is a Russia-aligned threat actor assessed with moderate confidence to operate in support of Russian interests. Active since at least August 2024, it is best known for operationalizing device code phishing against Microsoft cloud identities, abusing the legitimate OAuth device authorization flow to obtain access and refresh tokens without presenting victims with a fake login page. The actor has targeted governments, non-governmental organizations, defense organizations, and a range of other sectors across Europe, North America, Africa, and the Middle East. Storm-2372 commonly uses social-engineering lures themed around messaging and collaboration platforms, including Microsoft Teams-style invitations and outreach via commercial messaging applications, to persuade victims to enter attacker-generated device codes into legitimate Microsoft authentication pages. After successful authentication, the actor steals authenticated sessions and uses Microsoft Graph for mailbox access, keyword searching, email collection, and exfiltration. It has also used compromised internal accounts to send additional phishing messages, enabling follow-on compromise and lateral spread within victim organizations. By February 2025, Storm-2372 had evolved its tradecraft to abuse the Microsoft Authentication Broker client in the device code flow to obtain refresh tokens that supported downstream device registration in Entra ID and subsequent acquisition of Primary Refresh Tokens, improving persistence and access to organizational resources. Reporting also links the cluster technically to later Midnight Blizzard sub-cluster activity, with overlaps in device code phishing, OAuth code phishing, Microsoft Graph-based email exfiltration, and similar victimology. Storm-2372 is described as an initial-access operations sub-cluster associated with Midnight Blizzard, also known as APT29 or Cozy Bear.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Early adopter of device code phishing in a major campaign, compromising organizations across multiple industries and regions.
Related activity cluster mentioned for technical overlaps with Storm-2945, particularly device code phishing and exfiltration via Microsoft Graph.
Activity cluster tracked by Microsoft and associated here with ARToken, a phishing-as-a-service platform abusing the OAuth 2.0 device authorization grant to steal Microsoft 365 access and refresh tokens, bypass MFA, persist via broker/PRT-enabled flows, and enable business email compromise and tenant takeover actions.
Referenced as a Midnight Blizzard initial access sub-cluster known for device code and OAuth code phishing, Microsoft Graph-based email exfiltration, and related tradecraft similar to Storm-2945.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.