Microsoft Warns OAuth Redirect Abuse Delivers Malware to Government Targets
ID: e2f6259a-3dd8-5dcb-8fe1-cc05c1f56955
STIX ID: report--e2f6259a-3dd8-5dcb-8fe1-cc05c1f56955
Feed Name: The Hacker News
Microsoft warns of phishing campaigns that abuse legitimate OAuth redirection behavior to redirect victims to attacker-controlled pages; attackers register malicious OAuth applications, craft links (using manipulated parameters such as state) and distribute them via email or PDFs to target government and public-sector recipients. The campaigns deliver ZIP archives that unpack a LNK which runs PowerShell for reconnaissance, extracts an MSI that drops a decoy and sideloads a malicious DLL to decrypt and run a final payload in memory, establishing C2; some operations use AitM phishing frameworks like EvilProxy to intercept credentials. Microsoft removed identified malicious apps and advises restricting user consent, reviewing app permissions, and removing unused/overprivileged applications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
