Threat actors misuse OAuth applications to automate financially driven attacks | Microsoft Security Blog
microsoft.com · 3,854 words · saved by 1 readers
Microsoft presents cases of threat actors misusing OAuth applications as automation tools in financially motivated attacks.
Threat actors are misusing OAuth applications as an automation tool in financially motivated attacks. OAuth is an open standard for token-based authentication and authorization that enables applications to get access to data and resources based on permissions set by a user. Threat actors compromise user accounts to create, modify, and grant high privileges to OAuth applications that they can misuse to hide malicious activity. The misuse of OAuth also enables threat actors to maintain access to applications even if they lose access to the initially compromised account. In attacks observed by…
saved by
related reading
- Common Oauth Apps Used in Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- When MFA isn’t an option: The legacy of ROPC | Red Canaryredcanary.com
- Exposing and shutting down an inbox heist in actionredcanary.com
- Cloud coverage: Detecting an email payroll diversion attackredcanary.com
- Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- Responding to Adversary in the Middle attacksinvictus-ir.com
- Entra ID service principals in business email compromise schemes | Red Canaryredcanary.com
- Email Compromise To Mass Phishing Campaigndarktrace.com
- Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert networkmicrosoft.com
- Legacy authentication: The curious case of BAV2ROPCredcanary.com
- The Soze Syndicate - Business Email Compromise Campaign | Todyltodyl.com