logo

Oluomo: Microsoft OAuth AiTM Phishing Using a Naturalization-Form Lure

ID: e87642fe-c0dd-563d-bb37-9c47cefeb3ee

STIX ID: report--e87642fe-c0dd-563d-bb37-9c47cefeb3ee

Feed Name: Censys Blog

Threat Score
72/100

Date Published: 2026-04-22

Date Updated: 2026-04-27

...
...

Since November 2025 Censys tracked an AiTM phishing cluster called OLUOMO that uses compromised business websites as first-stage lures (displaying a U.S. naturalization petition image) and Azure Web Apps as second-stage proxies. A registered service worker on the proxy origin intercepts and serializes Microsoft OAuth traffic, exfiltrating credentials and tokens to attacker-controlled endpoints (credential routing via portal.microsoftonline.com.orgid.com). The report details kit artifacts, domain/IP indicators, timelines, and assessments of targeting and operational tradecraft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.