216.73.216.226

OAuth redirection abuse enables phishing and malware delivery

· Published 02/03/2026 21:58 · Modified 03/03/2026 17:14

Export JSON

Essential information

Published
02/03/2026 21:58
Modified
03/03/2026 17:14
Tags
2026-03-02 endpoint evilproxy oauth phishing public sector
Related entities
7 techniques (mitre), 1 malware, 5 others

Description

Microsoft has discovered campaigns exploiting 's redirection mechanisms to bypass conventional defenses. Attackers create malicious applications with redirect URIs pointing to malicious domains, then distribute links prompting targets to authenticate. The attack abuses 's error handling to redirect users from trusted providers to attacker-controlled sites for or malware delivery. Campaigns targeted government and public sectors using e-signature, financial, and political lures. Some attacks led to malware downloads and compromise via PowerShell and DLL side-loading. Mitigation involves governing apps, limiting user consent, reviewing permissions, and implementing cross-domain detection across email, identity, and .

External references