logo

Find hidden malicious OAuth apps in Microsoft 365 using Cazadora

ID: a363ef56-7e0a-543b-a59d-d8f763a0069a

STIX ID: report--a363ef56-7e0a-543b-a59d-d8f763a0069a

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-10-20

Date Updated: 2026-07-19

Author: Sponsored by Huntress Labs

...
...

Huntress Labs describes a widespread, active abuse of Azure OAuth applications where attackers install or leverage legitimate apps (Traitorware) or craft malicious apps (Stealthware) to gain persistent delegated access in Microsoft 365 tenants; the report includes prevalence statistics (≈10% of surveyed tenants with Traitorware, 500+ Stealthware instances discovered), hunting heuristics (rare apps with powerful delegated permissions, specific naming patterns, anomalous reply URLs), and an open-source auditing tool (Cazadora) to help administrators enumerate and remediate rogue apps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.