HomeSecurityMalicious OAuth applications target Microsoft 365 accounts

Malicious OAuth apps target Microsoft 365 accounts

Hackers are promoting malicious Microsoft OAuth applications that disguise themselves as Adobe and DocuSign and attempt to deliver malware and account credentials Microsoft 365

OAuth Microsoft 365 accounts malware

Proofpoint discovered the malicious campaigns, which it described as "highly targeted. "

The malicious OAuth applications specifically mimic Adobe Drive, Adobe Drive X, Adobe Acrobat, and DocuSign. They request access to less sensitive permissions such as “profile,” “email,” and “openid” to avoid raising suspicion. However, if victims grant these permissions, the attackers will gain access to:

  • profile – Full name, User ID, Profile picture, Username
  • email – primary email address (without access to inbox)

See also: Phishing emails imitate Booking.com and distribute malware

The malicious applications are promoted through phishing emails, sent by charities or small companies, via compromised email accounts (possibly Office 365 accounts).

According to Proofpoint, the emails have targeted multiple industries in the US and Europe, including government agencies, healthcare organizations, supply chain, and retail. Some of the phishing emails use RFPs and contracts as bait to trick recipients into opening embedded links.

While the privileges from accepting the Microsoft OAuth application only provided limited data to attackers, the information could be used for more targeted attacks.

Additionally, once the OAuth application is granted permission, users are redirected to pages with fake forms to enter Microsoft 365 account credentials. In other cases, users are redirected to pages containing malware.

“In some cases, victims were redirected to an “O365 login” page (hosted on a malicious domain). Less than a minute after authorization, Proofpoint detected suspicious login activity on the account“.

Proofpoint said they could not identify the malware being distributed, but the attackers used a ClickFix social engineering. ClickFix is ​​a relatively new social engineering attack that displays fake errors on websites or phishing documents and then asks users to perform a “captcha” “fix” to view the content properly.

See also: USA: Phishing messages with alleged parking fines

However, these fake fixes are actually malicious PowerShell commands or other malicious commands that download and install malware on both Windows and Mac devices.

The attacks that Proofpoint observed are similar to those reported years ago, indicating that OAuth applications remain an effective way to compromise Microsoft 365 accounts without stealing credentials.

phishing

Users are advised to be cautious of permission requests made by OAuth and always verify their source and legitimacy before approving them.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

To check existing approvals, go to “My Apps” (myapplications.microsoft.com) → “Manage your apps” → and revoke any unrecognized apps.

See also: EncryptHub distributes ransomware and info-stealers via phishing, Trojanized Apps

Microsoft 365 administrators can also restrict users' permission to consent to third-party OAuth application requests. Azure AD Conditional Access must also be enabled to restrict access to only trusted applications , and Microsoft Defender for Office 365 must be configured to detect suspicious activity.

Equally important to preventing such attacks is training staff on new cyberthreats and attack methods. Inform employees not to approve applications if they are unsure of their origin and organize regular seminars on phishing and social engineering attacks.

Finally, conduct continuous security audits to immediately identify any security gaps or suspicious behavior.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS