#CloudExploitation
Storm-2372 exploited OAuth device code flow with dynamic code generation and short-lived cloud infrastructure to bypass MFA and evade detection. Techniques included clipboard hijacking and malicious inbox rules. #OAuthAttack #CloudExploitation #USA
Inside an AI-enabled device code phishing campaign
Microsoft Defender observed the Storm-2372 device code phishing campaign that abused the OAuth device code flow, dynamic on-demand code generation, and short-lived cloud infrastructure to bypass MFA and evade signature- and reputation-based controls. The campaign used automation platforms (e.g., Railway.com), cloud hosting (Vercel, Cloudflare Workers, AWS Lambda), clipboard hijacking, Microsoft Graph reconnaissance, and malicious inbox rules to maintain persistence and exfiltrate high-value email data. #Storm2372 #RailwayCom
www.hendryadrian.com
April 7, 2026 at 8:15 AM
February 9, 2026 at 5:00 PM
January 12, 2026 at 7:00 PM