logo

The Long-Lived Risk of Malicious OAuth Applications: A Practical Threat Hunting Guide for M365

ID: ad42b224-4abb-59c9-a7ec-17994415665b

STIX ID: report--ad42b224-4abb-59c9-a7ec-17994415665b

Feed Name: Cyera Research Labs

Threat Score
75/100

Date Published: 2026-02-23

Date Updated: 2026-04-27

...
...

This report details investigations into malicious Microsoft 365 applications that abused OAuth consent and application identities to persist undetected across customer tenants for years, enabling data access, large-scale exposure of sensitive records, and phishing/MFA-bypass activity; it documents known campaigns and homoglyph/impersonation techniques, lists IOCs, and provides metadata-first hunting and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.