Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Alerts on OAuth Redirect Exploitation in Phishing Attacks

Microsoft Alerts on OAuth Redirect Exploitation in Phishing Attacks

Posted on March 3, 2026 By CWS

Microsoft has raised an alert regarding a sophisticated phishing scheme that capitalizes on OAuth URL redirection to evade typical email and browser defenses. This warning, issued on Monday, highlights a targeted attack on governmental and public-sector entities designed to reroute victims to attacker-operated sites without compromising their authentication tokens. The core of this threat lies in exploiting OAuth’s native features, not software weaknesses or credential theft.

Exploiting OAuth Redirection

The phishing strategy manipulates OAuth’s legitimate redirection capabilities to deceive users. Attackers craft URLs associated with well-known identity providers such as Entra ID or Google Workspace. These URLs, though appearing harmless, ultimately guide users to malicious pages under the attackers’ control. This method involves creating a deceptive application within a compromised tenant, with the redirect URL leading to a malware-hosting rogue domain.

Once the phishing link is distributed, recipients are tricked into authenticating with the malicious app via an invalid scope. This results in their devices unknowingly downloading malware, often packaged in ZIP files. When unpacked, these files initiate PowerShell commands, DLL sideloading, and potentially pre-ransomware activities.

Technical Breakdown of the Attack

The ZIP archive includes a Windows shortcut (LNK) file that triggers a PowerShell command upon opening. The command conducts host reconnaissance, while the LNK file extracts an MSI installer, which deploys a decoy document and sideloads a harmful DLL, specifically ‘crashhandler.dll,’ using the legitimate ‘steam_monitor.exe’ binary. This DLL then decrypts and executes ‘crashlog.dat,’ establishing a connection to an external command-and-control server.

Phishing emails are crafted with themes like e-signature requests, Teams recordings, and financial or political issues to lure users. These emails, disseminated via mass-emailing tools or custom Python and Node.js solutions, embed links either in the email itself or within attached PDFs. To enhance credibility, attackers encode the target’s email address within the state parameter, populating it automatically on the phishing site.

Preventive Measures and Mitigation

Microsoft’s investigation has led to the removal of several malicious OAuth applications. To mitigate such risks, organizations are urged to restrict user consents, regularly audit application permissions, and eliminate unnecessary or excessively privileged apps. While some attacks deliver malware, others redirect users to phishing frameworks like EvilProxy, which intercept credentials and session cookies through adversary-in-the-middle tactics.

The ongoing challenge of protecting against such sophisticated phishing attacks underscores the importance of robust cybersecurity measures, particularly in sectors handling sensitive information. As threat actors continue to evolve their techniques, constant vigilance and proactive defense strategies are crucial for safeguarding organizational assets.

The Hacker News Tags:cyber attack, Cybersecurity, DLL Sideloading, Government, identity-based threat, malicious applications, Malware, Microsoft, OAuth, Phishing, PowerShell

Post navigation

Previous Post: CyberStrikeAI Tool Exploits Fortinet FortiGate Weaknesses
Next Post: Android Security Update Targets 129 Vulnerabilities

Related Posts

OFAC Sanctions North Korean IT Network Exploiting Remote Jobs OFAC Sanctions North Korean IT Network Exploiting Remote Jobs The Hacker News
How Attackers Exploit Cloud Misconfigurations Across AWS, AI Models, and Kubernetes How Attackers Exploit Cloud Misconfigurations Across AWS, AI Models, and Kubernetes The Hacker News
FedRAMP at Startup Speed: Lessons Learned FedRAMP at Startup Speed: Lessons Learned The Hacker News
WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More Stories The Hacker News
Critical MetInfo CMS Flaw Exploited for Code Execution Critical MetInfo CMS Flaw Exploited for Code Execution The Hacker News
ServiceNow AI Platform Security Flaw Under Attack ServiceNow AI Platform Security Flaw Under Attack The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Security Flaw in SharePoint Poses Major Threat
  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark