Phishing campaign exploits OAuth redirection to bypass defenses
ID: c57bc578-36df-5fed-94ef-15645391e39d
STIX ID: report--c57bc578-36df-5fed-94ef-15645391e39d
Feed Name: Security Affairs
Microsoft researchers warn of phishing campaigns that abuse OAuth redirect behavior and error-handling flows to bypass email and browser defenses and redirect government and public-sector users from trusted identity providers to attacker-controlled sites. Attackers register malicious OAuth apps or craft OAuth URLs (using parameters like prompt=none or invalid scopes) to trigger redirects that automatically download ZIP archives containing LNK shortcuts or HTML smuggling loaders; these execute PowerShell, perform reconnaissance, side-load rogue DLLs, and establish C2. Recommended mitigations include stricter OAuth app governance, limiting user consent, Conditional Access policies, and cross-domain detection across email, identity, and endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
