With Storm-2372 (2025), Russian threat actors used OAuth Device Code Phishing to abuse the device registration process to hijack the Primary Refresh Token. This session will recreate the attack, compare valid activity, showing logging, access policies and detection rules. Attendees will take away concrete implementation guidance and what can be changed to mitigate/detect/respond more effectively.