logo

Attackers abuse OAuth’s built-in redirects to launch phishing and malware attacks

ID: fb02e936-f78d-5b3d-ac08-770b9c6d5985

STIX ID: report--fb02e936-f78d-5b3d-ac08-770b9c6d5985

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-03-04

Date Updated: 2026-04-28

...
...

Researchers report attackers are abusing OAuth error redirects from major providers (Microsoft, Google) by initiating silent, intentionally failing authorization flows that cause the identity provider to redirect victims to attacker-controlled sites; from there attackers either present phishing/AitM pages to harvest credentials and MFA or deliver malware via automatic downloads, enabling account takeover or endpoint compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.