Executive Summary
Microsoft Defender Security Research has identified a sophisticated phishing campaign by Storm-2372 that leverages the OAuth 2.0 Device Code Authentication flow. By using the EvilToken Phishing-as-a-Service (PhaaS) toolkit, the actor has moved away from static scripts toward an AI-driven infrastructure that automates the generation of device codes in real-time. This approach effectively bypasses the standard 15-minute expiration window and renders many traditional MFA protections ineffective by decoupling the authentication session from the user's original context.
The attack chain involves highly personalized, AI-generated lures and a complex redirect infrastructure using serverless platforms like Vercel and AWS Lambda to evade detection. Once access is gained, the actor focuses on high-value targets in financial or executive roles, performing automated Microsoft Graph reconnaissance and establishing persistence through malicious inbox rules and Primary Refresh Token (PRT) generation. The use of legitimate PaaS providers like Railway.com allows their backend polling nodes to blend into normal enterprise cloud traffic, posing a significant challenge for signature-based defenses.
