• News/
  • https://www.bleepingcomputer.com/news/security/microsoft-hackers-steal-emails-in-device-code-phishing-attacks/

Microsoft: Hackers steal emails in device code phishing attacks

BleepingComputer
·
Bill Toulas
·
Published Feb 15, 2025
·
Updated

An active campaign from a threat actor potentially linked to Russia is targeting Microsoft 365 accounts of individuals at organizations of interest using device code phishing. The targets are in the government, NGO, IT services and technology, defense, telecommunications, health, and energy/oil and gas sectors in Europe, North America, Africa, and the Middle East. Microsoft Threat Intelligence Center tracks the threat actors behind the device code phishing campaign as 'Storm-237', Based on interests, victimology, and tradecraft, the researchers have medium confidence that the activity is associated with a nation-state operation that aligns with Russia's interests. Input constrained devices - those that lack keyboard or browser support, like smart TVs and some IoTs, rely on a code authentication flow to allow allowing users to sign into an application by typing an authorization code on a separate device like a smartphone or computer. Microsoft researchers discovered that since last August, Storm-2372 abuses this authentication flow by tricking users into entering attacker-generated device codes on legitimate sign-in pages. The operatives initiate the attack after first establishing a connection with the target by "falsely posing as a prominent person relevant to the target" over messaging platforms like WhatsApp, Signal, and Microsoft Teams. The threat actor gradually establishes a rapport before sending a fake online meeting invitation via email or message. According to the ...

Read full article

Affected Software

2 affected components
Microsoft Microsoft 365
Microsoft Microsoft Entra ID
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a threat actor potentially linked to Russia conducting device code phishing attacks to steal emails from Microsoft 365 accounts.

2

What security implications are discussed in the article?

The article highlights the risks associated with device code phishing attacks targeting high-profile organizations, which could lead to unauthorized access and data breaches.

3

What products or software are affected by the phishing attacks?

The phishing attacks specifically target Microsoft 365 accounts and Microsoft Entra ID.

4

Who are the primary targets of these phishing attacks?

The primary targets include individuals in government, NGOs, IT services, and technology organizations.

5

What method is used by the hackers in these attacks?

The hackers use device code phishing as their method for stealing emails and accessing accounts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Microsoft: Hackers steal emails in device code phishing attacks - SecAlerts