Microsoft Corp. has issued a warning about a Russian-aligned hacker group, identified as Storm-2372, employing a technique known as 'device code phishing' to compromise Microsoft 365 accounts. The campaign, active since August 2024, targets various sectors including government, NGOs, IT services, defense, telecommunications, health, higher education, and energy across regions such as Europe, North America, Africa, and the Middle East. The hackers use messaging apps like WhatsApp, Signal, and Microsoft Teams to impersonate prominent individuals and trick users into entering attacker-generated device codes on legitimate sign-in pages. This method allows the attackers to capture authentication tokens, granting them access to the victim's accounts and data without needing passwords. Microsoft has observed the group using these tokens to access email and cloud storage, and to move laterally within networks by sending phishing messages from compromised accounts.
#Tecnología | ¿Tu computadora ha sido hackeada? 🛡️ Aquí te damos pasos vitales para proteger tu información y recuperar el control. 💻 https://t.co/l8D1GptC9R
Salt Typhoon remains active, hits more telecom networks via Cisco routers. The Chinese nation-state threat group intruded five additional telecom networks between Dec and Jan, including two unnamed providers in the U.S., Recorded Future researchers said. https://t.co/uHgC4FXNMU https://t.co/45sfnPMntU
a new type of scam scammer shares a private youtube video with u so it seems like its from credible source it's a deepfake video of the CEO of YouTube, telling the viewers that they need to follow a phishing link in the description to not to get demonetized @YouTubeCreators https://t.co/aVFQwo6diR