Skip to content

Leadership1 publisher2 min readPublished

Microsoft folds Storm-2372 into Midnight Blizzard 17 months after first naming it

The device code phishing cluster Microsoft disclosed in February 2025 is now assessed as an initial access arm of Midnight Blizzard. The sign-in flow the campaign abused works as designed, so the remedy is configuration.

The Board Room · Leadership desk

Illustration accompanying Microsoft folds Storm-2372 into Midnight Blizzard 17 months after first naming it

What happened

  • The campaign has been running since August 2024, with lures built to resemble the messaging experiences of WhatsApp, Signal and Microsoft Teams.
  • Targets have included government, NGOs, IT services, defense, telecommunications, health, higher education and energy firms in Europe, North America, Africa and the Middle East.
  • In device code phishing, the actor captures authentication tokens from the sign-in flow and uses them to reach the account and any data or services that account can open.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • cost Switching the flow off across a tenant is cheap to configure and expensive to prepare: someone has to find every input-constrained device that signs in this way before the policy goes on.
  • exposure Containment here is token revocation: a user who completed one of these sign-ins stays reachable while the tokens remain valid, with no second trick required.
  • precedent Microsoft says it is tracking other groups using the same technique, including ones documented by Volexity, so a decision about the device code flow applies to them too.

A device code exists for hardware that cannot open a browser, so the person signs in on a second device and types a short code to finish the authentication [7]. Storm-2372 generated the code itself and delivered it inside what looked like a Microsoft Teams meeting invitation; when the target completed the sign-in, the actor collected the valid access token and the authenticated session with it [5]. Microsoft wrote that the tokens "are part of an industry standard" and that it has not "found any vulnerabilities in our code base enabling this activity" [6]. That leaves nothing to patch. The decision is a configuration one: whether the flow is permitted in the tenant, and for which clients.

Blocking specific client IDs is easy to evade, and a blocklist written against the application identities seen in one week has to be maintained at that pace. One day after the February 13, 2025 post, Microsoft reported observing the actors move to the specific client ID for Microsoft Authentication Broker in the device code sign-in flow [2][8][11].

Microsoft's Storm numbers are provisional by design. The company uses them for an unknown, emerging or developing cluster until it reaches high confidence about the origin or identity behind the activity [9]. The July 31, 2026 update keeps the number and places the cluster inside Midnight Blizzard as a sub-cluster of initial access operations, on the basis of technical and operational overlaps [1]. It gives no confidence level for the assessment and does not describe Midnight Blizzard's sponsorship [10]. The moderate-confidence language about Russian interests, victimology and tradecraft attaches to the original reading of Storm-2372 [3].

The dates matter to anyone re-reading an old ticket. Activity dates to August 2024 and the disclosure to February 13, 2025, about six months later [4][8][12], and the attribution update landed roughly 17 months after the post [11].

The update changes the assumed consequence of one stolen token. "Initial access operations" is Microsoft's own description of a group whose output is entry into environments, and the technique can hold that entry for as long as the tokens stay valid [1][13]. An incident closed in 2025 as credential theft was scoped against Storm-2372 before Microsoft placed it inside Midnight Blizzard.

Microsoft said its Threat Intelligence Center continues to track campaigns launched by Storm-2372 and, when able, directly notifies customers who have been targeted or compromised [14].

What to watch

  • Whether Microsoft retires the Storm-2372 designation entirely and reports the activity under the Midnight Blizzard name.
  • Another first-party client ID appearing in the device code sign-in flow after Microsoft Authentication Broker.
  • New Microsoft or Volexity reporting that puts device code phishing in the hands of a further named cluster.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories