OAuth Hijack: Phishing Campaigns Weaponize Legitimate Redirection to Bypass Defenses
ID: 0db42c97-9bdd-57cd-bcc8-9510f06d3fb4
STIX ID: report--0db42c97-9bdd-57cd-bcc8-9510f06d3fb4
Feed Name: securityonline.info
Microsoft Defender researchers uncovered sophisticated phishing campaigns that weaponize OAuth redirect URIs on trusted identity provider domains (e.g., Entra ID, Google Workspace) to bypass email/browser filters, harvest credentials, and deliver malware. The five-stage chain moves victims from a deceptive OAuth consent/authentication flow to an attacker-controlled landing page where a ZIP is auto-downloaded; the ZIP contains LNK shortcuts that trigger PowerShell reconnaissance and launch a legitimate steam_monitor.exe to side-load a malicious crashhandler.dll which decrypts and executes an in-memory payload, establishing persistent C2. Microsoft has removed several malicious OAuth apps, but the use of legitimate redirection parameters remains a significant detection challenge.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
