Phishing with OAuth Redirect
ID: 886a5f43-6b96-54d3-9a38-90e257881597
STIX ID: report--886a5f43-6b96-54d3-9a38-90e257881597
Feed Name: LevelBlue SpiderLabs Blog
LevelBlue SpiderLabs reports January 2026 phishing campaigns abusing Microsoft Application Registration redirect URIs within the OAuth2 authorize flow to generate trustworthy-looking login.microsoftonline.com links that evade shallow URL inspection, route victims through workers.dev/CAPTCHA gates, and execute MitM Microsoft 365 phishing to steal credentials and MFA for session hijacking; the team notes a recurring client_id (1b6f59dd-45da-4ff7-9b70-36fb780f855b) and offers detection, hardening, and hunting guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
