
Device Code Phishing, Primary Refresh Tokens, and STORM-2372
Source: YouTube · Huntress · published Apr 21, 2026 · 15:27
BLUF: A February 2025 Microsoft advisory highlights a prolonged campaign by Russian threat actors exploiting device code phishing and OAuth API tokens to compromise Microsoft 365 and Google accounts 0:14.
Key Takeaways:
• The attack vector, identified as Storm 2372, potentially affects every Microsoft user and tenant, indicating a widespread risk 0:14.
• Threat actors have been active for approximately six to eight months, utilizing device code phishing as their primary method of intrusion 0:18.
• The campaign involves social engineering to obtain OAuth API tokens, leading to session hijacking and identity abuse across M365 and Google platforms 0:44.
• Microsoft issued an official advisory on February 13, 2025, marking a critical point in the disclosure and analysis of these ongoing threats 0:25.
Closing Statement: This summary underscores the urgency of addressing OAuth-based phishing vulnerabilities in enterprise environments. Organizations must prioritize monitoring for device code phishing attempts to mitigate ongoing identity compromise risks.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Okay. Thanks for coming. We've got identity abuse and m365. We're going to focus on m365. But Google is also very interesting. A lot of end users being compromised. And we want to drill down into
what's been happening. So from last year was storm 2372, which potentially affects every Microsoft user and tenant. And what's interesting is
if we start with a Microsoft advisory, which is typically the starting point,
February 13th, 2025 I'm just highlighting
some of the sort of important words. Right. So we see possible Russian threat actors going on for maybe eight months,
six months at the time. Device code phishing,
real big attack vector. So that's OAuth API tokens. We have social engineering of some kind
because it's OAuth tokens. It's a session hijack, sir. Come on in. Thanks for joining.…