logo

6 Months of Researching OAuth Application Attacks | Huntress

ID: 35693bb2-6bfd-54a4-a1ca-8860a7176870

STIX ID: report--35693bb2-6bfd-54a4-a1ca-8860a7176870

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2025-02-10

Date Updated: 2026-04-28

...
...

This Huntress report describes how attackers abuse Azure/Microsoft 365 OAuth applications—both legitimate apps misused by adversaries (Traitorware) and custom malicious app registrations (Stealthware)—to gain persistent tenant access. The authors enumerated thousands of tenants, found ~10% prevalence of certain abused apps and hundreds of bespoke malicious apps, outline detection/hunting heuristics (rare apps, unusual names, suspicious reply URLs such as http://localhost:7823/access/), and released an open-source audit tool (Cazadora) to help admins find and remediate malicious service principals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.