logo

Microsoft: Hackers abuse OAuth error flows to spread malware

ID: 64a0d4b9-3208-5d46-8cd9-d5555faf80c3

STIX ID: report--64a0d4b9-3208-5d46-8cd9-d5555faf80c3

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-03-03

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Microsoft Defender observed targeted campaigns abusing legitimate OAuth redirect behavior to force authentication errors and redirect government and public-sector users to attacker-controlled pages. Attackers register malicious OAuth apps, use invalid parameters (e.g., scope, prompt=none) to trigger silent redirects, and funnel victims to phishing pages (EvilProxy) or to ZIP downloads containing .LNK files and HTML smuggling that launch PowerShell, enabling DLL side-loading and in-memory payload execution; defenders are advised to tighten OAuth app permissions, enforce strong identity/Conditional Access policies, and use cross-domain detection across email, identity, and endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.