Storm-2372 AI-Driven Device Code Phishing Campaign
Score: 9/10

Storm-2372 AI-Driven Device Code Phishing Campaign

The threat actor Storm-2372 is utilizing the EvilToken Phishing-as-a-Service (PhaaS) toolkit to execute automated, AI-enhanced device code phishing attacks against organizational accounts.

Executive Summary

Microsoft Defender Security Research has identified a sophisticated phishing campaign by Storm-2372 that leverages the OAuth 2.0 Device Code Authentication flow. By using the EvilToken Phishing-as-a-Service (PhaaS) toolkit, the actor has moved away from static scripts toward an AI-driven infrastructure that automates the generation of device codes in real-time. This approach effectively bypasses the standard 15-minute expiration window and renders many traditional MFA protections ineffective by decoupling the authentication session from the user's original context.

The attack chain involves highly personalized, AI-generated lures and a complex redirect infrastructure using serverless platforms like Vercel and AWS Lambda to evade detection. Once access is gained, the actor focuses on high-value targets in financial or executive roles, performing automated Microsoft Graph reconnaissance and establishing persistence through malicious inbox rules and Primary Refresh Token (PRT) generation. The use of legitimate PaaS providers like Railway.com allows their backend polling nodes to blend into normal enterprise cloud traffic, posing a significant challenge for signature-based defenses.

Key Details

Threat Name

EvilToken Phishing-as-a-Service

Affects

—

Adversary

Storm-2372

Malware/Tools

EvilToken

Report Score

9out of 10
Quality Score
Excellent
IOC Quality6
TTP Details9
Detection Guidance10
Enterprise Relevance10
Clarity & Structure9
Technical Depth8

Sources