Microsoft warns of OAuth phishing campaigns capable of bypassing email and browser defenses: it says that “these campaigns demonstrate that this abuse is operational, not theoretical.”



  • Microsoft warns that hackers are abusing OAuth redirect feature to distribute malware
  • Phishing emails related to Teams recordings or 365 resets redirect victims to attacker-controlled sites
  • Payloads sent via ZIP files with LNK shortcuts and HTML smuggling; The final stage connects to the external C2.

Hackers are abusing a redirect feature in OAuth to infect people’s computers with malware and steal their login credentials, Microsoft warns.

OAuth (short for Open Authorization) is a system that allows users to log into websites using their account from another service, without giving their password to that website. Whenever a “Sign in with Google” pop-up appears, it is most likely OAuth.



Leave a Comment

Your email address will not be published. Required fields are marked *