logo

Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs

ID: 4231cf67-3a8c-5e14-9304-465ab72c2a48

STIX ID: report--4231cf67-3a8c-5e14-9304-465ab72c2a48

Feed Name: Wiz Blog

Threat Score
75/100

Date Published: 2026-02-18

Date Updated: 2026-05-01

...
...

This report documents multiple coordinated campaigns (including a large 2025 campaign and legacy 2019 homoglyph campaigns) in which attackers register malicious OAuth applications to trick users into granting consent in Microsoft Entra ID, creating persistent service principals that bypass MFA and enable long-term access to mail and files; the authors describe an automated detection pipeline ("OAuth Apps Scout"), enumerate TTPs and IOCs, and provide actionable defenses such as restricting user consent, auditing OAuth grants, and monitoring first-time applications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.