logo

Phishing campaign exploits OAuth redirection to bypass defenses

ID: c57bc578-36df-5fed-94ef-15645391e39d

STIX ID: report--c57bc578-36df-5fed-94ef-15645391e39d

Feed Name: Security Affairs

Threat Score
72/100

Date Published: 2026-03-03

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Microsoft researchers warn of phishing campaigns that abuse OAuth redirect behavior and error-handling flows to bypass email and browser defenses and redirect government and public-sector users from trusted identity providers to attacker-controlled sites. Attackers register malicious OAuth apps or craft OAuth URLs (using parameters like prompt=none or invalid scopes) to trigger redirects that automatically download ZIP archives containing LNK shortcuts or HTML smuggling loaders; these execute PowerShell, perform reconnaissance, side-load rogue DLLs, and establish C2. Recommended mitigations include stricter OAuth app governance, limiting user consent, Conditional Access policies, and cross-domain detection across email, identity, and endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.