Common Oauth Apps Used in Business Email Compromise – Syne's Cyber Corner
This article serves as another place to document some common (and not so common) Oauth applications that are abused for malicious purposes during a BEC. Some are well documented, while others are rarer, only discussed between responders or detailed on GitHub lists. The places where some of these apps are detailed may only provide a brief summary of the application, while this article aims to provide more information on the potential use and impact of those less common applications. For more details on the apps such as their App ID and MITRE details, check out the below two links. https://github.com/randomaccess3/detections/blob/main/M365_Oauth_Apps/MaliciousOauthAppDetections.json https://huntresslabs.github.io/rogueapps (Click an application to go directly to it’s entry.) This is one of the most documented and abused applications. In a tenant the application will show up as PERFECTDATA SOFTWARE, but the real software behind it is called Email Backup Wizard. It is a desktop application
Posted in Azure AD Forensics Incident Response Office 365 Posted by By syne0 August 29, 2024 No Comments This article serves as another place to document some common (and not so common) Oauth applications that are abused for malicious purposes during a BEC. Some are well documented, while others are rarer, only discussed between responders or detailed on GitHub lists. The places where some of these apps are detailed may only provide a brief summary of the application, while this article aims to provide more information on the potential use and impact of those less common applications. For more
Explore this link on the map →saved by
related reading
- Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- Malicious Usage of eM Client In Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- Cloud coverage: Detecting an email payroll diversion attackredcanary.com
- Entra ID service principals in business email compromise schemes | Red Canaryredcanary.com
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- Email Compromise To Mass Phishing Campaigndarktrace.com
- Exposing and shutting down an inbox heist in actionredcanary.com
- The Soze Syndicate - Business Email Compromise Campaign | Todyltodyl.com
- When MFA isn’t an option: The legacy of ROPC | Red Canaryredcanary.com
- Legacy authentication: The curious case of BAV2ROPCredcanary.com
- Apolloapp.apollo.io
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com