Attackers abuse OAuth’s built-in redirects to launch phishing and malware attacks
ID: fb02e936-f78d-5b3d-ac08-770b9c6d5985
STIX ID: report--fb02e936-f78d-5b3d-ac08-770b9c6d5985
Feed Name: Malwarebytes Blog
Threat Score
Researchers report attackers are abusing OAuth error redirects from major providers (Microsoft, Google) by initiating silent, intentionally failing authorization flows that cause the identity provider to redirect victims to attacker-controlled sites; from there attackers either present phishing/AitM pages to harvest credentials and MFA or deliver malware via automatic downloads, enabling account takeover or endpoint compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
