logo

Phishing with OAuth Redirect

ID: 886a5f43-6b96-54d3-9a38-90e257881597

STIX ID: report--886a5f43-6b96-54d3-9a38-90e257881597

Feed Name: LevelBlue SpiderLabs Blog

Date Published: 2026-02-18

Date Updated: 2026-04-28

Author: Federico Cedolini

...
...

LevelBlue SpiderLabs reports January 2026 phishing campaigns abusing Microsoft Application Registration redirect URIs within the OAuth2 authorize flow to generate trustworthy-looking login.microsoftonline.com links that evade shallow URL inspection, route victims through workers.dev/CAPTCHA gates, and execute MitM Microsoft 365 phishing to steal credentials and MFA for session hijacking; the team notes a recurring client_id (1b6f59dd-45da-4ff7-9b70-36fb780f855b) and offers detection, hardening, and hunting guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.