logo

OAuth redirection abuse enables phishing and malware delivery

ID: 51800fd8-38a1-58e8-8f98-fd26014f90b1

STIX ID: report--51800fd8-38a1-58e8-8f98-fd26014f90b1

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2026-03-02

Date Updated: 2026-04-28

Author: Microsoft Defender Security Research Team

...
...

Microsoft Defender researchers observed active phishing campaigns that exploit legitimate OAuth authorization/error redirect behavior (e.g., prompt=none and invalid scopes) to silently redirect targets—especially government and public-sector users—to attacker-controlled landing pages. The redirected pages have been used to deliver ZIP payloads containing LNK shortcuts and HTML smuggling loaders that trigger PowerShell execution, DLL side‑loading, and remote C2 activity; the report includes IOCs (client IDs, domains, hashes), detection queries, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.