New Phishing Wave Uses OAuth Prompts to Take Over Microsoft Accounts
## Phishing Campaign Targeting Microsoft Accounts via OAuth Authentication
Phishing Campaign Targeting Microsoft Accounts via OAuth Authentication
A recent phishing campaign has been identified targeting Microsoft account holders by exploiting OAuth authentication prompts. Instead of directly requesting passwords, the attack involves tricking users into granting permissions to malicious applications via seemingly legitimate Microsoft authorization screens.
This approach circumvents traditional password protection and multi-factor authentication, posing significant risks to both individuals and organizations. Security researchers have observed a rise in these sophisticated attacks, where phishing emails direct recipients to click links leading to fraudulent or compromised OAuth consent screens.
Upon clicking to grant permissions, attackers gain access tokens, allowing them to control Microsoft accounts without requiring the password.
The phishing emails often mimic trusted sources, using urgent language to prompt user actions. When users engage with the link, they encounter an authentic-looking Microsoft login page, followed by an OAuth permission prompt. This prompt, using genuine Microsoft branding, exploits user familiarity with such screens.
A recent phishing campaign has been identified targeting Microsoft account holders by exploiting OAuth authentication prompts.
Once permission is granted, attackers obtain OAuth tokens, providing full account access. These tokens remain valid even if passwords are changed or additional security measures are implemented.
The attack can impact business users significantly, granting potential access to sensitive corporate data, confidential communications, and customer information. Compromised accounts may facilitate lateral movement within corporate networks, enabling the spread of malicious activities and intelligence gathering.
Users are advised to avoid clicking links in unexpected emails leading to authorization screens and instead access Microsoft account settings directly through a browser. Scrutinize permission requests, especially if an application requests suspicious access levels, and decline if necessary. Organizations should implement security tools to monitor unusual OAuth token usage and suspicious application permissions. Enable all available security features, including conditional access policies to identify unusual sign-in locations and device usage patterns. Conduct security awareness training focused on OAuth phishing techniques, ensuring employees recognize the importance of scrutinizing permission prompts.
Based on reporting by GBHackers.
