Microsoft warns of OAuth phishing campaigns that can bypass email and browser defenses – says “these campaigns demonstrate that this exploit is operational, not theoretical”


  • Microsoft warns that hackers are abusing the OAuth redirection feature to deliver malware
  • Phishing emails with the theme Teams recordings or 365 reset redirect victims to attacker-controlled websites
  • Payload dropped via ZIP archives with LNK shortcuts and HTML smuggling; last stage connects to external C2

Hackers are abusing a redirection feature in OAuth to infect people’s computers with malware and steal their login credentials, Microsoft warns.

OAuth (short for Open Authorization) is a system that lets users log into websites using their account from another service, without giving the website their password. When a “Sign in with Google” popup appears, it’s most likely OAuth.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top