Find hidden malicious OAuth apps in Microsoft 365 using Cazadora
ID: a363ef56-7e0a-543b-a59d-d8f763a0069a
STIX ID: report--a363ef56-7e0a-543b-a59d-d8f763a0069a
Feed Name: Bleeping Computer
Huntress Labs describes a widespread, active abuse of Azure OAuth applications where attackers install or leverage legitimate apps (Traitorware) or craft malicious apps (Stealthware) to gain persistent delegated access in Microsoft 365 tenants; the report includes prevalence statistics (≈10% of surveyed tenants with Traitorware, 500+ Stealthware instances discovered), hunting heuristics (rare apps with powerful delegated permissions, specific naming patterns, anomalous reply URLs), and an open-source auditing tool (Cazadora) to help administrators enumerate and remediate rogue apps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
