HomeSecurityMicrosoft: Phishing attacks via OAuth are evolving

Microsoft: OAuth phishing attacks are evolving

Microsoft warns that attackers are exploiting a built -in behavior of the OAuth authentication protocol to redirect victims to malware using links that point to legitimate identity provider domains (e.g. Microsoft Entra ID and Google Workspace). The links appear safe but ultimately lead to fake sites.

OAuth phishing

" OAuth includes a legitimate feature that allows identity providers to redirect users to a specific landing page under certain conditions, typically in error scenarios or other defined flows ," the Security Microsoft Defender Research Team wrote in a blog post.

«Attackers can abuse this native functionality by creating URLs with popular identity providers, such as Entra ID or Google Workspace, that use forged parameters or associated malicious applications to redirect users to pages controlled by the attackers.».

See also: Hackers use CyberStrikeAI for AI-powered attacks

The company said it has disabled several applications OAuth linked to the activity, but warned that the campaigns are ongoing and require continued monitoring.

Phishing via OAuth: How the attack works

The attack begins with phishing emails, with bait appearing as electronic signature requests, communications from the HR department, Microsoft Teams meeting invitations, and password reset notifications. The emails contain malicious links, either embedded in the body of the email or within a PDF attachment.

The link points to a real OAuth authorization point but is crafted with intentionally “broken” parameters. The attackers use a “prompt=none” value, requesting silent authentication without a login screen, and combine it with an invalid scope value. The combination is designed to fail. When it fails, the identity provider redirects the user’s browser to a URI registered by the attacker.

Microsoft: OAuth phishing attacks are evolving

"While this behavior is compliant with standards, attackers can abuse it to redirect users through trusted authorization points to destinations controlled by them," the researchers wrote in the post.

The technique represents a structural shift in the way attackers approach identity, said Sanchit Vir Gogia, principal analyst at Greyhound Research . “ The first step is real. The browser behaves correctly. The identity provider behaves correctly. The trust signal is authentic ,” he said. “ This shifts phishing from brand-layer deception to workflow-layer manipulation .”

See also: Fake Google Security site steals MFA codes

In one campaign described by Microsoft in a blog post, the redirect delivered a ZIP file containing a malicious shortcut file. Opening the file triggered a PowerShell script that executed reconnaissance commands and eventually connected to a server controlled by the attacker. Microsoft described the subsequent activity as consistent with behavior prior to the ransomware attack.

Other campaigns, described in the post, directed victims to adversary-in-the-middle frameworks, such as EvilProxy, to collect credentials and session cookies.

Context is the new red flag

Sakshi Grover, Research Director at IDC Asia/Pacific, said that the familiar advice of checking a link to verify its domain is no longer sufficient and does not apply in environments where authentication flows typically go through trusted identity providers.

“Organizations need to shift the message from ‘check the link’ to ‘validate the context,’” he said. “Employees need to be trained to question whether an authentication request is expected, whether it aligns with a current business activity , and whether the application is requesting permissions that make sense.”

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Gogia said businesses need to go further and change the underlying behavior completely. “Never start authentication journeys from unsolicited inbound links,” he said. “Authentication should start from controlled starting points, not from email triggers.”

See also: Vulnerability in MS-Agent allows complete system compromise

Microsoft: OAuth phishing attacks are evolving

The governance vacuum exploited by attackers

Both analysts pointed to the governance of OAuth applications as the deepest structural gap exploited by this campaign.

IDC's Grover said that governance maturity remains uneven across enterprises. "Broad default consent settings and limited monitoring of redirected URIs remain common, particularly in environments where cloud and SaaS adoption has outpaced identity governance controls," she said. The scale of the problem is easy to underestimate, according to Greyhound Research's Gogia.

“Every SaaS integration, workflow automation, and collaboration tool can require an application registration. Over time, tenants accumulate hundreds or thousands of registered applications. Redirect URIs are configured during setup and rarely revisited,” he said. “The telemetry is there. The interpretation is not.”

Microsoft said in the blog post that organizations should limit user consent to third-party OAuth apps, regularly review app permissions , and remove apps that are unused or offer excessive privileges.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS