Creating a Malicious Azure AD OAuth2 Application
ID: 64f7de3d-c327-55b8-b3e4-55341d744f00
STIX ID: report--64f7de3d-c327-55b8-b3e4-55341d744f00
Feed Name: TrustedSec blog
This blog post is a step-by-step malicious playbook for building and operating a malicious OAuth web application that abuses Azure AD and Microsoft Graph to phish users, enumerate organization users, and exfiltrate mailbox contents. It covers LAMP server setup, deploying CoasterKaty's PHPAzureADoAuth code, database/configuration changes, registering Azure AD apps (including creating client secrets and configuring scopes), handling unverified vs verified publisher constraints, adding Graph API calls to harvest users and emails, persisting stolen data to disk, and an insider-compromise variant that targets only an organization’s tenant to gain broader access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
