Microsoft warns of OAuth phishing campaigns able to bypass email and browser defenses – says ‘these campaigns demonstrate that this abuse is operational, not theoretical’



  • Microsoft warns hackers are abusing OAuth redirect feature to deliver malware
  • Phishing emails themed around Teams recordings or 365 resets redirect victims to attacker-controlled sites
  • Payloads dropped via ZIP archives with LNK shortcuts and HTML smuggling; final stage connects to external C2

Hackers are abusing a redirect feature in OAuth to infect people’s computers with malware and steal their login credentials, Microsoft is warning.

OAuth (short for Open Authorization) is a system which lets users log into websites using their account from another service, without giving that website their password. Whenever a “Log In With Google” popup is shown, it is most likely OAuth.


https://cdn.mos.cms.futurecdn.net/CT482eMSRL8PagRtuBVYNd-2000-80.jpeg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img