Cyberatackers Russos saw Microsoft teams with a new Phishing campaign



  • Microsoft has seen a new phishing attack vector in nature
  • Storm-2372 is stealing access tokens through Microsoft equipment
  • The group has been linked to Russia with medium confidence

A new Phishing campaign has been seen using the “device code phishing” through Microsoft equipment to lead governments, NGOs and other industries in Europe, North America, Africa and the Middle East.

The attack, seen by Microsoft himself, takes advantage of the invitations of videoconation meetings of the equipment that incites the victim to enter a device code generated by the attacker that results in the victim to deliver valid access tokens, giving the attacker Access to emails of victims and confidential data.

Leave a Comment

Your email address will not be published. Required fields are marked *