Threats Tagged 'oauth'
View all threats tagged with 'oauth'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'oauth'
Click on any threat for detailed analysis and mitigation recommendations
Huntress researchers discovered Knight Office, a phishing kit utilizing Adversary-in-the-Middle techniques to steal Microsoft 365 session tokens. The attack chain begins with DocuSign-themed phishing emails containing redirects through Monday.com and compromised Joomla websites. Victims are directed to credential capture pages where session tokens are harvested and fed into the Knight Office console. These stolen tokens enable attackers to bypass multi-factor authentication entirely by using already-authenticated sessions. In one incident, attackers registered rogue devices in Microsoft Entra ID and bound Windows Hello for Business credentials for persistence. Analysis revealed nine phishing attacks linked to this kit over two weeks, with hundreds of related emails reported since April. The console, hosted at IP 104.37.188.94, manages at least 25 phishing domains using .vu top-level domains. Join the discussion | AlienVault OTX General | 09/02/2026, 13:39:03 UTC Added: 09/02/2026, 16:22:27 UTC |
In early 2026, phishing attacks remain a top threat vector in security operations. This analysis covers a novel attack method exploiting Microsoft's OAuth 2.0 Device Authorization Grant (Device Code Flow) to compromise user accounts. Attackers use phishing emails containing Mailchimp's Mandrill service links to bypass security controls, leading victims to fake Adobe-themed websites. The sites abuse legitimate Microsoft authentication mechanisms to obtain access and refresh tokens, granting persistent delegated access to critical resources like Graph API, Teams, Outlook, and SharePoint. The technique leverages shared client IDs across tenants and family of client IDs (FOCI) for lateral movement. Two variants exist: one using external phishing infrastructure with dynamic code generation, and another relying solely on fake meeting invitations containing pre-generated device codes. The attack is particularly effective as it uses legitimate Microsoft services, making detection challenging. Join the discussion | AlienVault OTX General | 04/20/2026, 20:30:02 UTC Added: 04/21/2026, 09:31:05 UTC |
A new phishing technique abusing Microsoft's OAuth Device Code flow is on the rise, with over 180 phishing URLs detected in a week. This method shifts from credential theft to token-based account takeover, making detection more challenging. Attackers initiate a device authorization process, tricking victims into approving it on legitimate Microsoft pages. The attack uses encrypted HTTPS traffic and legitimate authentication flows, bypassing traditional phishing indicators. Victims unknowingly grant attackers access to their Microsoft 365 accounts through OAuth tokens. This poses a critical risk as it allows immediate access to corporate data and resources, potentially leading to business email compromise and persistent access through refresh tokens. Join the discussion | AlienVault OTX General | 03/11/2026, 06:17:03 UTC Added: 03/11/2026, 10:28:55 UTC |
Microsoft has discovered phishing campaigns exploiting OAuth's redirection mechanisms to bypass conventional defenses. Attackers create malicious applications with redirect URIs pointing to malicious domains, then distribute phishing links prompting targets to authenticate. The attack abuses OAuth's error handling to redirect users from trusted providers to attacker-controlled sites for phishing or malware delivery. Campaigns targeted government and public sectors using e-signature, financial, and political lures. Some attacks led to malware downloads and endpoint compromise via PowerShell and DLL side-loading. Mitigation involves governing OAuth apps, limiting user consent, reviewing permissions, and implementing cross-domain detection across email, identity, and endpoint. Join the discussion | AlienVault OTX General | 03/02/2026, 21:58:21 UTC Added: 03/03/2026, 17:02:26 UTC |
This analysis reveals the growing threat of malicious OAuth applications in Microsoft Entra ID, which attackers use for persistence and privilege escalation. The report details how these apps blend in with legitimate integrations, making detection challenging. It describes the creation of OAuth Apps Scout, an automated detection pipeline that identifies emerging malicious OAuth apps. The research uncovered multiple campaigns, including one involving 19 apps impersonating well-known brands. The report compares tactics from 2019 to 2025, showing an evolution in attacker strategies from Microsoft impersonation to third-party SaaS spoofing. It concludes with actionable defense strategies for organizations to protect against these threats. MediumCampaign Join the discussion | AlienVault OTX General | 02/19/2026, 11:04:36 UTC Added: 02/19/2026, 12:50:31 UTC |
A malware campaign discovered on the NuGet package repository targets the cryptocurrency ecosystem by distributing 14 malicious packages impersonating legitimate crypto-related tools. These packages employ techniques such as homoglyphs, version bumping, and inflated download counts to appear trustworthy and evade detection. The malware aims to steal crypto funds by redirecting transactions and exfiltrating secrets, including OAuth tokens for Google Ads accounts. The campaign highlights the risks of software supply chain attacks, especially for projects relying on compromised dependencies. No known exploits in the wild have been reported yet, but the threat poses a significant risk to developers and organizations integrating these packages. The attack affects . NET developers using NuGet packages related to cryptocurrency and OAuth services. The severity is assessed as medium due to the potential confidentiality and financial impact, combined with moderate exploitation complexity. European organizations involved in blockchain development, fintech, and digital advertising are particularly at risk. Mitigation requires strict dependency vetting, use of package integrity verification, and monitoring of OAuth token usage. Join the discussion | AlienVault OTX General | 12/17/2025, 21:22:37 UTC Added: 12/17/2025, 23:15:13 UTC |
The ToddyCat APT group has developed advanced tools and techniques to covertly access corporate email data by targeting both on-premises Outlook OST files and Microsoft 365 cloud environments. Their toolkit includes PowerShell-based TomBerBil for extracting browser data, TCSectorCopy for copying Outlook OST files, and methods to steal OAuth tokens from Microsoft 365 processes. They leverage SMB for remote file access, dump process memory, and search for access tokens to bypass security monitoring. These tactics enable stealthy data theft of sensitive email content and credentials. Detection guidance is available for each technique to help defenders identify and mitigate these intrusions. The threat is assessed as medium severity due to the complexity and targeted nature of the attacks, with no known exploits in the wild yet. European organizations using Microsoft 365 and Outlook are at risk, especially those with valuable email communications and cloud integrations. Join the discussion | AlienVault OTX General | 11/21/2025, 14:38:00 UTC Added: 11/21/2025, 22:16:22 UTC |
Two cyber criminal groups, UNC6040 and UNC6395, are targeting organizations' Salesforce platforms for data theft and extortion. UNC6040 uses social engineering, particularly voice phishing, to gain access to Salesforce accounts. They trick employees into granting access or sharing credentials, then use API queries or malicious connected apps to exfiltrate data. UNC6395 exploits compromised OAuth tokens for the Salesloft Drift application to access Salesforce instances. Both groups have been observed exfiltrating large volumes of customer data. Victims of UNC6040 have received extortion emails demanding cryptocurrency payments to prevent data publication. The FBI has provided numerous IP addresses and other indicators of compromise associated with these groups, along with recommended mitigations to enhance security and prevent such attacks. Join the discussion | AlienVault OTX General | 09/15/2025, 14:01:00 UTC Added: 09/15/2025, 14:13:16 UTC |
In June 2025, Google's Salesforce instance was breached by UNC6040 & UNC6240 using vishing, OAuth app abuse, and anonymity layers. The attackers stole business data of small and medium-sized clients. A parallel attack by UNC6395 compromised Salesloft Drift's Salesforce integration, affecting hundreds of customers. Both incidents involved sophisticated social engineering, OAuth token abuse, and data exfiltration via TOR. The attacks are linked to the ShinyHunters group and share similarities with other high-profile breaches targeting various industries. The incidents highlight vulnerabilities in SaaS environments and the need for improved security measures, including OAuth governance, identity management, and proactive monitoring. Join the discussion | AlienVault OTX General | 09/03/2025, 15:30:53 UTC Added: 09/03/2025, 20:17:47 UTC |
Proofpoint has uncovered a sophisticated phishing campaign utilizing fake Microsoft OAuth applications to bypass multifactor authentication and steal credentials. The threat actors impersonate various enterprise apps like RingCentral, SharePoint, Adobe, and DocuSign to lure victims. The attack chain involves OAuth app creation, redirects to malicious URLs, and the use of attacker-in-the-middle phishing kits, predominantly Tycoon. This technique has been observed in email campaigns with over 50 impersonated applications, targeting multiple industries. The campaign's goal is to gain access to Microsoft 365 accounts, potentially for information gathering, lateral movement, malware installation, or further phishing attacks. Join the discussion | AlienVault OTX General | 08/01/2025, 15:39:42 UTC Added: 08/04/2025, 10:32:35 UTC |
Showing 1 to 10 of 10 results