Storm-2372
- Origin
- RU
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:20:35
Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications
Targeted regions: country_code:eu country_code:na country_code:af country_code:me
Context
Storm-2372 is a suspected nation-state actor aligned with Russian interests, engaging in device code phishing campaigns targeting governments, NGOs, and various industries across Europe, North America, Africa, and the Middle East. The actor employs tactics that involve impersonating prominent individuals through third-party messaging services like WhatsApp and Signal to gain rapport before sending phishing invitations. These invitations lure users into completing device code authentication requests, granting Storm-2372 initial access to victim accounts and enabling Graph API data collection activities, including email harvesting. Microsoft has observed the actor utilizing keyword searches within compromised accounts to exfiltrate sensitive information.
Reports & references
- Microsoft — Storm 2372 Conducts Device Code Phishing Campaign (report)
- raw.githubusercontent.com — Microsoftmapping (report)