Malicious OAuth apps target Microsoft 365 accounts

bleepingcomputer.com

Cybercriminals are using fake Microsoft OAuth apps that appear to be Adobe and DocuSign to steal Microsoft 365 account credentials. These malicious apps request minimal permissions to avoid detection and are part of targeted phishing campaigns. The attacks involve emails from compromised accounts, often posing as charities or small businesses. They target various industries, including government and healthcare, using tactics like contract lures to trick users into granting access. Once permission is granted, users are redirected to phishing pages or malware downloads. Experts warn users to verify OAuth app requests and check their app permissions regularly to protect their accounts.


With a significance score of 3.4, this news ranks in the top 14% of today's 15487 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 9000 minimalists.


loading...