Threat actors misuse OAuth applications to automate financially driven attacks
ID: 88d20f42-e023-5218-9a91-0fb2e94796b6
STIX ID: report--88d20f42-e023-5218-9a91-0fb2e94796b6
Feed Name: Microsoft Security
Microsoft Threat Intelligence describes active financially motivated campaigns abusing OAuth applications: attackers (including tracked clusters like Storm-1283 and Storm-1286) compromise accounts via phishing, AiTM proxying, and password spraying, create or modify OAuth apps with high privileges, and use them to deploy Azure VMs for cryptomining (causing $10k–$1.5M in compute charges), maintain persistence after BEC reconnaissance, and send large-scale phishing/spam (observed ~17,000 malicious apps and >927,000 phishing emails); the report includes detections, mitigation guidance, and hunting queries for Microsoft security products.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
