Threat Intelligence / Actor / Storm-2372
Storm-2372
As of 2026-09-27, Storm-2372 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 4 threats spanning phishing. Also known as EvilTokens, Kali365, APT29, Cozy Bear. ATT&CK coverage spans 68 techniques across 13 tactics in 4 of 4 tracked threats. Most-observed techniques: T1528 (Steal Application Access Token), T1566 (Phishing), T1583 (Acquire Infrastructure).
Also known as: EvilTokens, Kali365, APT29, Cozy Bear, Midnight Blizzard, UTA0304, UTA0307, UNK_AcademicFlare, _eviltokensadmin_, IRON RITUAL, IRON HEMLOCK, NobleBaron
ATT&CK techniques observed
- T1528 Steal Application Access Token — Credential Access — observed in 4 of 4 tracked threats
- T1566 Phishing — Initial Access — observed in 4 of 4 tracked threats
- T1583 Acquire Infrastructure — Resource Development — observed in 4 of 4 tracked threats
- T1087 Account Discovery — Discovery — observed in 3 of 4 tracked threats
- T1098 Account Manipulation — Persistence — observed in 3 of 4 tracked threats
- T1102 Web Service — Command and Control — observed in 3 of 4 tracked threats
- T1114 Email Collection — Collection — observed in 3 of 4 tracked threats
- T1526 Cloud Service Discovery — Discovery — observed in 3 of 4 tracked threats
- T1550 Use Alternate Authentication Material — Lateral Movement — observed in 3 of 4 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltration — observed in 3 of 4 tracked threats
- T1598 Phishing for Information — Reconnaissance — observed in 3 of 4 tracked threats
- T1606 Forge Web Credentials — Credential Access — observed in 3 of 4 tracked threats
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 4 tracked threats
- T1071 Application Layer Protocol — Command and Control — observed in 2 of 4 tracked threats
- T1078 Valid Accounts — Persistence — observed in 2 of 4 tracked threats
Tracked threats
- Microsoft Entra ID Device Code Phishing — OAuth 2.0 Device Authorization Grant Abuse (Storm-2372, EvilTokens, Kali365) — HIGH
- EvilTokens Phishing-as-a-Service: Microsoft OAuth 2.0 Device Authorization Grant (Device Code) Phishing Against Microsoft 365 — HIGH
- Microsoft 365 Device Code Phishing Campaign Abusing the OAuth 2.0 Device Authorization Grant Flow (EvilTokens PhaaS) — HIGH
- Device Code Phishing Surge — 37x Increase Driven by EvilTokens and VENOM PhaaS Kits Targeting Microsoft 365 — HIGH
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →