Microsoft OAuth URL used as redirect to AITM credential phishing site · Blog · Sublime Security
ID: 7273a7d9-be2d-572a-932c-efa45223c983
STIX ID: report--7273a7d9-be2d-572a-932c-efa45223c983
Feed Name: Sublime Security Blog
Sublime Security describes an active credential-phishing campaign that uses legitimate Microsoft OAuth authorization flows and app consent pages as an evasion technique to capture credentials and session IDs. The attack typically starts with fake password-reset messages that link to a Microsoft login with embedded parameters, then redirects victims through a malicious app consent (featuring an Adobe logo) and Cloudflare Turnstile to a secondary login page, allowing attackers to harvest credentials. Sublime documents detection signals and provides links to detection rules and prevention guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
