Russian cyberattackers spotted hitting Microsoft Teams with new phishing campaign

Posted by:
James Thompson
Thu, 06 Mar
0 Comment
Feature image

A new phishing attack vector, named Storm-2372, has been identified by Microsoft targeting governments, NGOs, and various industries across Europe, North America, Africa, and the Middle East. The attackers are using ‘device code phishing’ through Microsoft Teams to steal access tokens from victims. This allows them to gain access to sensitive data including emails. The group behind the attack, linked with medium confidence to Russia, uses tactics like building rapport with victims, sending fake device code authentication requests, and lateral movement using the stolen tokens. To combat this threat, Microsoft advises disabling device code flow, providing phishing training, revoking access tokens suspected of being compromised, and implementing sign-in risk-based policies.

Tags:

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments