They Didn't Steal Your Password. They Used the Login Page Against You.
ID: 23ca0f45-991c-528d-addf-ea3cc7541bc6
STIX ID: report--23ca0f45-991c-528d-addf-ea3cc7541bc6
Feed Name: NoHackie
This report summarizes Microsoft Defender research describing an active phishing campaign that weaponizes OAuth’s by-design error redirects (using manipulated parameters like prompt=none and invalid scopes) to move victims from legitimate Microsoft/Google auth endpoints to attacker-controlled pages; outcomes include EvilProxy-mediated credential and session cookie capture (MFA bypass) or automatic malware delivery that culminates in DLL sideloading via steam_monitor.exe/crashhandler.dll and subsequent hands-on-keyboard activity. Defenses recommended include restricting app registration, auditing OAuth apps, hunting for OAuth authorization URL patterns and error indicators, deploying image-load and DLL-sideloading detections, enforcing Continuous Access Evaluation and device-bound tokens, and adopting phishing-resistant FIDO2 passkeys for high-value accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
