Microsoft Alerts Customers to New Phishing Attack Exploiting OAuth in Entra ID to Bypass Detection
ID: 8f114228-dbcc-5cdf-bc02-c1659374fd78
STIX ID: report--8f114228-dbcc-5cdf-bc02-c1659374fd78
Feed Name: GBHackers
Microsoft uncovered targeted phishing and malware campaigns abusing OAuth 2.0 redirection to silently redirect victims (often government and public-sector) to attacker-controlled sites. Adversaries create legitimate-looking OAuth apps, force error redirects using parameters like prompt=none and scope=invalid, pass victim emails via the state parameter to pre-fill phishing pages, and either intercept sessions with tools like EvilProxy or trigger automatic ZIP downloads that side-load malicious DLLs (steam_monitor.exe -> crashhandler.dll). The report includes IOCs (file names, Defender signatures, error codes), recommended governance and detection controls, and hunting guidance for telemetry involving invalid OAuth scopes and post-redirect payload downloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
