Oluomo: Microsoft OAuth AiTM Phishing Using a Naturalization-Form Lure
ID: e87642fe-c0dd-563d-bb37-9c47cefeb3ee
STIX ID: report--e87642fe-c0dd-563d-bb37-9c47cefeb3ee
Feed Name: Censys Blog
Since November 2025 Censys tracked an AiTM phishing cluster called OLUOMO that uses compromised business websites as first-stage lures (displaying a U.S. naturalization petition image) and Azure Web Apps as second-stage proxies. A registered service worker on the proxy origin intercepts and serializes Microsoft OAuth traffic, exfiltrating credentials and tokens to attacker-controlled endpoints (credential routing via portal.microsoftonline.com.orgid.com). The report details kit artifacts, domain/IP indicators, timelines, and assessments of targeting and operational tradecraft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
