Russian Cyberattackers discovered to hit Microsoft -team with new phishing -campaign


  • Microsoft has seen a new phishing -attack vector in nature
  • Storm-2372 steals the access tokens through Microsoft team
  • The group has been attached to Russia with medium confidence

A new phishing campaign has been viewed using ‘Device Code Phishing’ through Microsoft Teams to target governments, NGOs and other industries throughout Europe, North America, Africa and the Middle East.

The attack, discovered by Microsoft himself, exploits Team’s video conference invitations that ask the victim to enter a device code generated by the striker, resulting in the victim handing over valid access tokens, giving the striker access to victims -e emails and sensitive Data.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top