6 Months of Researching OAuth Application Attacks | Huntress
ID: 35693bb2-6bfd-54a4-a1ca-8860a7176870
STIX ID: report--35693bb2-6bfd-54a4-a1ca-8860a7176870
Feed Name: Huntress Blog
This Huntress report describes how attackers abuse Azure/Microsoft 365 OAuth applications—both legitimate apps misused by adversaries (Traitorware) and custom malicious app registrations (Stealthware)—to gain persistent tenant access. The authors enumerated thousands of tenants, found ~10% prevalence of certain abused apps and hundreds of bespoke malicious apps, outline detection/hunting heuristics (rare apps, unusual names, suspicious reply URLs such as http://localhost:7823/access/), and released an open-source audit tool (Cazadora) to help admins find and remediate malicious service principals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
