logo

Phish of the day: Microsoft OAuth scams abuse redirects for malware delivery

ID: fb861dec-fa9f-538e-a944-6820cd6e770c

STIX ID: report--fb861dec-fa9f-538e-a944-6820cd6e770c

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2026-03-03

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Microsoft warns of active OAuth redirection abuse campaigns targeting government and public-sector organizations: attackers use crafted OAuth authorization URLs (triggering error-based redirects) in phishing emails or PDFs to send victims to attacker-controlled landing pages hosting ZIPs that use HTML smuggling and LNK shortcuts to run PowerShell, side-load a malicious DLL (crashhandler.dll) via a legitimate executable (steam_monitor.exe) and establish outbound C2 connections. Campaigns leveraged phishing-as-a-service (EvilProxy), cloud infrastructure, and mass-sending tools; Microsoft disabled malicious OAuth apps but related activity persists and requires ongoing monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.