logo

Microsoft Warns OAuth Redirect Abuse Delivers Malware to Government Targets

ID: e2f6259a-3dd8-5dcb-8fe1-cc05c1f56955

STIX ID: report--e2f6259a-3dd8-5dcb-8fe1-cc05c1f56955

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-03-03

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Microsoft warns of phishing campaigns that abuse legitimate OAuth redirection behavior to redirect victims to attacker-controlled pages; attackers register malicious OAuth applications, craft links (using manipulated parameters such as state) and distribute them via email or PDFs to target government and public-sector recipients. The campaigns deliver ZIP archives that unpack a LNK which runs PowerShell for reconnaissance, extracts an MSI that drops a decoy and sideloads a malicious DLL to decrypt and run a final payload in memory, establishing C2; some operations use AitM phishing frameworks like EvilProxy to intercept credentials. Microsoft removed identified malicious apps and advises restricting user consent, reviewing app permissions, and removing unused/overprivileged applications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.