# Storm-2372

> As of 2026-09-27, Storm-2372 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 4 threats spanning phishing. Also known as EvilTokens, Kali365, APT29, Cozy Bear. ATT&CK coverage spans 68 techniques across 13 tactics in 4 of 4 tracked threats. Most-observed techniques: T1528 (Steal Application Access Token), T1566 (Phishing), T1583 (Acquire Infrastructure).

- **Nation:** Russia
- **Tracked threats:** 4
- **Categories:** PHISHING
- **Also known as:** EvilTokens, Kali365, APT29, Cozy Bear, Midnight Blizzard, UTA0304, UTA0307, UNK_AcademicFlare, _eviltokensadmin_, IRON RITUAL, IRON HEMLOCK, NobleBaron
- **As of:** 2026-09-27

## ATT&CK techniques observed

68 techniques observed across 4 of 4 tracked threats. Tactics: Resource Development (12), Stealth (formerly Defense Evasion) (8), Credential Access (7), Persistence (7), Initial Access (6), Reconnaissance (6).

- [T1528](https://attack.mitre.org/techniques/T1528/) Steal Application Access Token — Credential Access — observed in 4 of 4 tracked threats
- [T1566](https://attack.mitre.org/techniques/T1566/) Phishing — Initial Access — observed in 4 of 4 tracked threats
- [T1583](https://attack.mitre.org/techniques/T1583/) Acquire Infrastructure — Resource Development — observed in 4 of 4 tracked threats
- [T1087](https://attack.mitre.org/techniques/T1087/) Account Discovery — Discovery — observed in 3 of 4 tracked threats
- [T1098](https://attack.mitre.org/techniques/T1098/) Account Manipulation — Persistence — observed in 3 of 4 tracked threats
- [T1102](https://attack.mitre.org/techniques/T1102/) Web Service — Command and Control — observed in 3 of 4 tracked threats
- [T1114](https://attack.mitre.org/techniques/T1114/) Email Collection — Collection — observed in 3 of 4 tracked threats
- [T1526](https://attack.mitre.org/techniques/T1526/) Cloud Service Discovery — Discovery — observed in 3 of 4 tracked threats
- [T1550](https://attack.mitre.org/techniques/T1550/) Use Alternate Authentication Material — Lateral Movement — observed in 3 of 4 tracked threats
- [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration Over Web Service — Exfiltration — observed in 3 of 4 tracked threats
- [T1598](https://attack.mitre.org/techniques/T1598/) Phishing for Information — Reconnaissance — observed in 3 of 4 tracked threats
- [T1606](https://attack.mitre.org/techniques/T1606/) Forge Web Credentials — Credential Access — observed in 3 of 4 tracked threats
- [T1027](https://attack.mitre.org/techniques/T1027/) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 2 of 4 tracked threats
- [T1071](https://attack.mitre.org/techniques/T1071/) Application Layer Protocol — Command and Control — observed in 2 of 4 tracked threats
- [T1078](https://attack.mitre.org/techniques/T1078/) Valid Accounts — Persistence — observed in 2 of 4 tracked threats

## Tracked threats

- [Microsoft Entra ID Device Code Phishing — OAuth 2.0 Device Authorization Grant Abuse (Storm-2372, EvilTokens, Kali365)](https://intel.threadlinqs.com/threat/TL-2026-0943) — HIGH
- [EvilTokens Phishing-as-a-Service: Microsoft OAuth 2.0 Device Authorization Grant (Device Code) Phishing Against Microsoft 365](https://intel.threadlinqs.com/threat/TL-2026-0888) — HIGH
- [Microsoft 365 Device Code Phishing Campaign Abusing the OAuth 2.0 Device Authorization Grant Flow (EvilTokens PhaaS)](https://intel.threadlinqs.com/threat/TL-2026-0824) — HIGH
- [Device Code Phishing Surge — 37x Increase Driven by EvilTokens and VENOM PhaaS Kits Targeting Microsoft 365](https://intel.threadlinqs.com/threat/TL-2026-0323) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Storm-2372
