UNIT.City — місце, де люди працюють... КРАЩЕ! Обирай свій простір просто зараз 👉

Microsoft has identified Russian hackers masquerading as officials from the US State Department and the Ukrainian Ministry of Defense to steal Microsoft 365 accounts

Microsoft Threat Intelligence Center researchers have uncovered a long-running campaign by Russian government hackers using sophisticated phishing techniques to steal Microsoft 365 accounts.

Leave a comment
Microsoft has identified Russian hackers masquerading as officials from the US State Department and the Ukrainian Ministry of Defense to steal Microsoft 365 accounts

Microsoft Threat Intelligence Center researchers have uncovered a long-running campaign by Russian government hackers using sophisticated phishing techniques to steal Microsoft 365 accounts.

«The Microsoft Threat Intelligence Center has identified an active and successful device code phishing campaign conducted by attackers known as Storm-2372. Our investigation shows that this campaign has been active since August 2024, when the attacker created decoys that resembled messaging apps, including WhatsApp, Signal, and Microsoft Teams,» the researchers said in a statement.

They said Storm-2372 targets included government and non-government organizations, services and IT, defense, telecommunications, healthcare, higher education, and energy/oil and gas sectors in Europe, North America, Africa, and the Middle East. Microsoft assesses with «medium confidence» that Storm-2372 aligns with Russian interests, victimology, and technology.

What tool did the attackers choose?

Hackers have been using device code phishing, Ars Technica reports. It exploits device code flow, a form of authentication formalized in the OAuth industry standard. Device code flow authentication is designed to register printers, smart TVs, and other similar devices with accounts. These devices typically don’t support browsers, making it difficult to log in using more standard forms of authentication, such as usernames, passwords, and two-factor authentication.

Instead of authenticating the user directly, the restricted device displays a letter or alphanumeric code for the device along with a link associated with the user’s account. The user opens the link on a computer or other device that makes it easier to log in and enters the code. The remote server then sends a token to the restricted device, which registers it with the account.

Device authorization occurs in two ways: one from an application or code running on a restricted device that requests permission to log in, and the other from the device’s browser that the user typically uses to log in to their account.

How hackers operated

In advisories, both Volexity and Microsoft warn that threat actors working on behalf of the Russian government have been abusing this flow since at least August of last year to take over Microsoft 365 accounts. The attackers masquerade as trusted high-ranking officials and initiate conversations with targeted users on messengers such as Signal, WhatsApp, and Microsoft Teams.

Among the organizations they are impersonating are:

  • US Department of State.
  • Ministry of Defense of Ukraine.
  • Parliament of the European Union.
  • Well-known research institutions.
Example of phishing correspondence with hackers

Once contact is established, attackers ask the user to join a Microsoft Teams meeting, grant access to apps and data as an external Microsoft 365 user, or join a chat in a secure app. The request includes a link and a passcode that the attacker generated using a device under their control.

When the victim clicks the link using a browser authorized to access their Microsoft 365 account and enters the code, the attacker’s device gains access that lasts as long as the authentication tokens remain valid.

The effectiveness of the attacks is largely a result of the ambiguity of the user interface of the device code authorization process. This means it is important for people to pay close attention to the links and the pages they lead to.

Read the country's main IT news in our Telegram
Read the country’s main IT news in our Telegram
On the topic
Read the country’s main IT news in our Telegram
Hackers from the Russian Sandworm group are attacking Ukrainian users who use pirated Windows KMS activators
Hackers from the Russian Sandworm group are attacking Ukrainian users who use pirated Windows KMS activators
On the topic
Hackers from the Russian Sandworm group are attacking Ukrainian users who use pirated Windows KMS activators
Police arrest 4 Russians who lead 8bas ransomware hacking group that carried out over 1,000 attacks worldwide
Police arrest 4 Russians who lead 8bas ransomware hacking group that carried out over 1,000 attacks worldwide
On the topic
Police arrest 4 Russians who lead 8bas ransomware hacking group that carried out over 1,000 attacks worldwide
UPD. Russian hackers took responsibility for the global ChatGPT outage. Why did they take down the most popular AI?
UPD. Russian hackers took responsibility for the global ChatGPT outage. Why did they take down the most popular AI?
On the topic
UPD. Russian hackers took responsibility for the global ChatGPT outage. Why did they take down the most popular AI?
Also Read
Call of Duty не зникне з PlayStation раптово. Sony отримала таку гарантію під Microsoft, яка купує розробника гри – Activision Blizzard
Call of Duty не зникне з PlayStation раптово. Sony отримала таку гарантію під Microsoft, яка купує розробника гри – Activision Blizzard
Call of Duty не зникне з PlayStation раптово. Sony отримала таку гарантію під Microsoft, яка купує розробника гри – Activision Blizzard
У Microsoft визнали, що PS4 продаються у два рази краще, ніж Xbox
У Microsoft визнали, що PS4 продаються у два рази краще, ніж Xbox
У Microsoft визнали, що PS4 продаються у два рази краще, ніж Xbox
Microsft опубліковала аналіз кібервійни в Україні та розкрила, які групи хакерів пов’язані з ФСБ, ГРУ
Microsft опубліковала аналіз кібервійни в Україні та розкрила, які групи хакерів пов’язані з ФСБ, ГРУ
Microsft опубліковала аналіз кібервійни в Україні та розкрила, які групи хакерів пов’язані з ФСБ, ГРУ
Meta, Microsoft та інші великі компанії об'єдналися задля створення стандартів для метавсесвітів
Meta, Microsoft та інші великі компанії об'єдналися задля створення стандартів для метавсесвітів
Meta, Microsoft та інші великі компанії об'єдналися задля створення стандартів для метавсесвітів

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.