logo

Creating a Malicious Azure AD OAuth2 Application

ID: 64f7de3d-c327-55b8-b3e4-55341d744f00

STIX ID: report--64f7de3d-c327-55b8-b3e4-55341d744f00

Feed Name: TrustedSec blog

Threat Score
75/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This blog post is a step-by-step malicious playbook for building and operating a malicious OAuth web application that abuses Azure AD and Microsoft Graph to phish users, enumerate organization users, and exfiltrate mailbox contents. It covers LAMP server setup, deploying CoasterKaty's PHPAzureADoAuth code, database/configuration changes, registering Azure AD apps (including creating client secrets and configuring scopes), handling unverified vs verified publisher constraints, adding Graph API calls to harvest users and emails, persisting stolen data to disk, and an insider-compromise variant that targets only an organization’s tenant to gain broader access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.