logo

Microsoft Alerts Customers to New Phishing Attack Exploiting OAuth in Entra ID to Bypass Detection

ID: 8f114228-dbcc-5cdf-bc02-c1659374fd78

STIX ID: report--8f114228-dbcc-5cdf-bc02-c1659374fd78

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-04

Date Updated: 2026-04-22

Author: Divya

...
...

Microsoft uncovered targeted phishing and malware campaigns abusing OAuth 2.0 redirection to silently redirect victims (often government and public-sector) to attacker-controlled sites. Adversaries create legitimate-looking OAuth apps, force error redirects using parameters like prompt=none and scope=invalid, pass victim emails via the state parameter to pre-fill phishing pages, and either intercept sessions with tools like EvilProxy or trigger automatic ZIP downloads that side-load malicious DLLs (steam_monitor.exe -> crashhandler.dll). The report includes IOCs (file names, Defender signatures, error codes), recommended governance and detection controls, and hunting guidance for telemetry involving invalid OAuth scopes and post-redirect payload downloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.