Russian Hackers Outsmart MFA with New Device Code Phishing Tactic
Storm-2372, a Russian APT group, has leveled up their game by using device code phishing to sidestep Multi-Factor Authentication. They’re hacking into major sectors like government and healthcare without even bothering with passwords. It’s like breaking into Fort Knox using a paperclip and a clever disguise.

Hot Take:
Looks like Storm-2372 is redefining the term “storming the gates.” Forget the medieval battering rams; these guys are using device code phishing to casually stroll past the guards, bypassing Multi-Factor Authentication like it’s a mere speed bump on the information superhighway. Time to upgrade those castle defenses, folks!
Key Points:
- Storm-2372, a Russian APT group, uses device code phishing to bypass MFA.
- The group targets high-value sectors: government, technology, finance, defense, and healthcare.
- Device code phishing exploits the OAuth device authorization flow to gain unauthorized access.
- Hackers create realistic fake login pages to trick users into entering device codes.
- The attack can provide access to Microsoft email accounts for up to three months.
Already a member? Log in here