Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligencegovernment-diplomatic-threatinitial-access-methodidentity-authentication-vulnerability

Microsoft Reports OAuth Redirect Abuse Used to Deliver Malware to Government Targets

Updated 3mo agoFirst seen Mar 3, 20268 sources

Microsoft reported phishing campaigns targeting government and public-sector organizations that abuse legitimate OAuth redirect behavior in identity providers (including Microsoft Entra ID and Google Workspace) to send victims from seemingly benign authorization URLs to attacker-controlled infrastructure. The technique does not rely on exploiting a software vulnerability or stealing OAuth tokens; instead, attackers register a malicious OAuth application in a tenant they control, then send victims an OAuth link that triggers an error flow (e.g., via an intentionally invalid scope) to force a redirect to a rogue domain hosting malware. Microsoft said the delivered payloads have included ZIP archives that lead to execution chains involving LNK-based execution, PowerShell, and DLL side-loading, consistent with follow-on hands-on-keyboard or pre-ransomware activity.

Microsoft stated it disabled the identified malicious OAuth applications in Entra ID, but warned that related OAuth abuse activity persists and requires continued monitoring. Reported lures used in the phishing emails included e-signature requests, access to Teams meeting recordings, Microsoft 365 password reset instructions, and political themes; Microsoft also observed indicators consistent with the use of free mass-mailing tools and custom tooling (including Python and Node.js) to distribute the campaigns and deliver malware capable of endpoint takeover.

Share:
Microsoft Reports OAuth Redirect Abuse Used to Deliver Malware to Government Targets
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Mar 3, 20264mo ago

Microsoft publishes warning and mitigation guidance on OAuth abuse

Microsoft Defender researchers publicly warned about the campaigns and said the activity abuses standards-compliant OAuth redirect behavior rather than a software vulnerability. Microsoft recommended tighter OAuth app governance, restricting user consent, reviewing and removing risky app permissions, and improving cross-domain detection across email, identity, and endpoints.

Microsoft disables malicious OAuth applications during investigation

During its investigation, Microsoft identified and removed or disabled several malicious OAuth applications used in the campaigns within Microsoft Entra ID. The company noted that related OAuth abuse activity was still continuing and required ongoing monitoring.

Attackers use redirected victims for credential theft and malware delivery

Microsoft documented that redirected victims were sent either to adversary-in-the-middle phishing infrastructure such as EvilProxy to steal credentials and session cookies, or to malware-delivery chains. One observed infection path delivered ZIP files with LNK and HTML smuggling components, followed by PowerShell reconnaissance, DLL sideloading via steam_monitor.exe, and an in-memory payload communicating with command-and-control infrastructure.

Phishing campaigns abuse OAuth redirects against public-sector targets

Threat actors launched ongoing phishing campaigns primarily targeting government and public-sector organizations by abusing legitimate OAuth redirection and error-handling behavior in providers such as Microsoft Entra ID and Google Workspace. The attacks used crafted authorization URLs, including invalid scopes and prompt=none, to redirect victims from trusted identity-provider domains to attacker-controlled infrastructure.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

15 LINKEDOpen in app
Affected products
4 linked
Microsoft Entra IdSteamSteamPowershell
Organizations
8 linked
Microsoft CorporationGoogleValve CorporationThe RegisterAT&TMeta PlatformsAppleSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Microsoft Reports OAuth Redirect Abuse Used to Deliver Malware to Government Targets | Mallory