Microsoft warns that financially motivated malicious actors are using OAuth applications to automate BEC and phishing, spread spam, and install virtual machines for cryptomining.
See also: API vulnerabilities affected Grammarly, Vidio and Bukalapak

OAuth (short for Open Authorization) is an open standard for providing secure delegation to applicationsto access servers based on user-defined permissions through token-based authentication and authorization, without requiring the provision of credentials.
Recent incidents investigated by Microsoft have revealed that attackers are primarily targeting user accounts that lack strong authentication mechanisms (e.g., multi-factor authentication) in phishing or password-spraying attacks, focusing on those with permissions to create or modify OAuth applications.
The compromised accounts are then used to create new OAuth applications and grant them high privileges, allowing their malicious activities to remain hidden and ensuring continued access even if the original account is lost.
Highly privileged OAuth applications are used for a wide range of illicit activities, including deploying virtual machines dedicated to mining , securing continuous access for Business Email Compromise (BEC) attacks, and launching spam campaigns that exploit compromised domain names.
See also: Consent-phishing attack passes Microsoft's 'Verified Publisher' checks
An interesting example involves a threat actor detected as Storm-1283, which created an OAuth application to install virtual cryptocurrency mining machines. The financial impact on targeted organizations ranged from $10,000 to $1.5 million, depending on the duration of the attack.

Another attacker exploited OAuth applications created using compromised accounts to maintain persistence and execute phishing campaigns using an adversary-in-the-middle kit (AiTM phishing kit).
The same attacker used the compromised accounts to harvest data for Commercial Email Breach (BEC), using the Microsoft Outlook Web Application (OWA) to search for attachments related to the words “payment” and “invoice.”
In different cases, the attacker created multiple OAuth applications to maintain their persistent presence, adding new credentials and reading or sending phishing emails via the Microsoft Graph API.
One of the main signs that indicate a potential BEC attack is a change in the language or communication style in emails. Attackers may use different phrases, fonts, or signatures than the sender usually uses. This change can be a sign that someone else has taken control of the sender's email account.
See also: ownCloud: Critical vulnerabilities expose credentials
Another sign of a potential BEC attack is a request to change banking information or instructions to transfer money. Attackers may pose as high-ranking employees or associates and ask recipients to change banking information or make money transfers to accounts controlled by the attackers.
Another sign of a potential BEC attack is an unexpected change in email recipients. Attackers may add or remove recipients from emails, causing confusion and disruption. This could mean that someone has compromised the sender's email account and is trying to gain access to sensitive information.
Finally, threats or pressure for immediate response are another sign of a potential BEC attack. Attackers may pretend to have an emergency or threaten legal consequences if their demands are not met immediately. This type of pressure can be a sign that something is not right and that careful analysis should be done before deciding on any action.
Source: bleepingcomputer
