logo

Threat actors misuse OAuth applications to automate financially driven attacks

ID: 88d20f42-e023-5218-9a91-0fb2e94796b6

STIX ID: report--88d20f42-e023-5218-9a91-0fb2e94796b6

Feed Name: Microsoft Security

Threat Score
78/100

Date Published: 2023-12-12

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence describes active financially motivated campaigns abusing OAuth applications: attackers (including tracked clusters like Storm-1283 and Storm-1286) compromise accounts via phishing, AiTM proxying, and password spraying, create or modify OAuth apps with high privileges, and use them to deploy Azure VMs for cryptomining (causing $10k–$1.5M in compute charges), maintain persistence after BEC reconnaissance, and send large-scale phishing/spam (observed ~17,000 malicious apps and >927,000 phishing emails); the report includes detections, mitigation guidance, and hunting queries for Microsoft security products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.