Microsoft Warns of New Phishing Attack Exploiting OAuth in Entra ID to Evade Detection
ID: 7c00830d-69d7-58d0-8e73-65444dd7f668
STIX ID: report--7c00830d-69d7-58d0-8e73-65444dd7f668
Feed Name: cybersecurityNews.com
Microsoft-documented active phishing campaigns abuse OAuth's legitimate redirect/error handling in Microsoft Entra ID to perform silent authentication probes and redirect users to attacker-controlled infrastructure (e.g., EvilProxy), enabling credential/session interception, automated ZIP/HTML smuggling downloads, and endpoint persistence via DLL side-loading and C2. The report describes the crafted authorize endpoint parameters (response_type=code, prompt=none, invalid scope), use of the state parameter to encode victim emails, observed error redirect (65001), and recommended mitigations including restricting app consent, auditing app registrations, enabling Conditional Access, deploying cross-domain XDR, and monitoring OAuth redirect URIs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
