An active campaign from a threat actor potentially linked to Russia is targeting Microsoft 365 accounts of individuals at organizations of interest using device code phishing. The targets are in the government, NGO, IT services and technology, defense, telecommunications, health, and energy/oil and gas sectors in Europe, North America, Africa, and the Middle East. Microsoft Threat Intelligence Center tracks the threat actors behind the device code phishing campaign as 'Storm-237', Based on interests, victimology, and tradecraft, the researchers have medium confidence that the activity is associated with a nation-state operation that aligns with Russia's interests. Input constrained devices - those that lack keyboard or browser support, like smart TVs and some IoTs, rely on a code authentication flow to allow allowing users to sign into an application by typing an authorization code on a separate device like a smartphone or computer. Microsoft researchers discovered that since last August, Storm-2372 abuses this authentication flow by tricking users into entering attacker-generated device codes on legitimate sign-in pages. The operatives initiate the attack after first establishing a connection with the target by "falsely posing as a prominent person relevant to the target" over messaging platforms like WhatsApp, Signal, and Microsoft Teams. The threat actor gradually establishes a rapport before sending a fake online meeting invitation via email or message. According to the ...
Microsoft: Hackers steal emails in device code phishing attacks
BleepingComputer
·Bill Toulas
·Published Feb 15, 2025
·Updated
Affected Software
2 affected components
Microsoft Microsoft 365
Microsoft Microsoft Entra ID
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a threat actor potentially linked to Russia conducting device code phishing attacks to steal emails from Microsoft 365 accounts.
2
What security implications are discussed in the article?
The article highlights the risks associated with device code phishing attacks targeting high-profile organizations, which could lead to unauthorized access and data breaches.
3
What products or software are affected by the phishing attacks?
The phishing attacks specifically target Microsoft 365 accounts and Microsoft Entra ID.
4
Who are the primary targets of these phishing attacks?
The primary targets include individuals in government, NGOs, IT services, and technology organizations.
5
What method is used by the hackers in these attacks?
The hackers use device code phishing as their method for stealing emails and accessing accounts.