logo

Microsoft Warns of New Phishing Attack Exploiting OAuth in Entra ID to Evade Detection

ID: 7c00830d-69d7-58d0-8e73-65444dd7f668

STIX ID: report--7c00830d-69d7-58d0-8e73-65444dd7f668

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-03-03

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Microsoft-documented active phishing campaigns abuse OAuth's legitimate redirect/error handling in Microsoft Entra ID to perform silent authentication probes and redirect users to attacker-controlled infrastructure (e.g., EvilProxy), enabling credential/session interception, automated ZIP/HTML smuggling downloads, and endpoint persistence via DLL side-loading and C2. The report describes the crafted authorize endpoint parameters (response_type=code, prompt=none, invalid scope), use of the state parameter to encode victim emails, observed error redirect (65001), and recommended mitigations including restricting app consent, auditing app registrations, enabling Conditional Access, deploying cross-domain XDR, and monitoring OAuth redirect URIs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.