Wednesday, March 4, 2026
31.1 C
New Delhi

Microsoft Flags New OAuth-Based Phishing Attack Targeting Public Sector

Show Quick Read

Key points generated by AI, verified by newsroom

A new phishing campaign has been discovered that uses a clever trick inside the OAuth login system. Security researchers from Microsoft Defender say attackers are abusing the normal redirection feature of OAuth to send users to malicious websites. Unlike traditional phishing attacks that try to steal passwords or tokens directly, this method works differently. It triggers an error in the authentication process, so the system automatically redirects the victim’s browser. 

The campaign mainly targets government and public-sector organisations. Because the links use trusted identity provider domains, many security filters fail to detect the attack easily.

New OAuth Phishing Attack Uses Redirect Trick

This new OAuth phishing attack works by abusing the normal error-handling process defined in the OAuth standard. Attackers first register fake applications inside their own cloud tenants. They then configure redirect links that lead to domains they control.

Phishing emails are sent with special OAuth authorisation links. These links target the Microsoft Entra ID login endpoint and include parameters designed to break the login process. For example, attackers request an invalid permission, so the authentication attempt fails.

When the request fails, the identity system automatically redirects the browser to the attacker’s registered redirect link. Since this redirect is part of normal OAuth behaviour, many email and browser security systems do not block it.

Five-Stage Phishing Attack Chain Explained

Researchers say the campaign follows a five-stage phishing attack chain. First, attackers send phishing emails related to e-signatures, financial documents, or meeting invites. Automated tools help them send large numbers of messages.

Second, clicking the link triggers a silent OAuth check. The link may also contain the victim’s encoded email address.

Third, the authentication request fails, and the system redirects the user to the attacker’s website. Fourth, victims may be taken to phishing pages or prompted to download malicious ZIP files.

Finally, malware can run PowerShell commands, collect system information, and connect to attacker-controlled servers.

Go to Source

Hot this week

UAE travel alert: Air Arabia extends flight suspension to March 9, what travellers need to know

Air Arabia Air Arabia has extended the suspension of its flights to and from the UAE until 15:00 (UAE time) on Monday, March 9, 2026, while allowing a limited number of services to operate in coordination with authorities. Read More

Iran postpones Khamenei’s funeral citing anticipated massive crowds

Iran announced that a state funeral for supreme leader Ayatollah Ali Khamenei, which had been planned for Wednesday evening in Tehran, was postponed “in anticipation of unprecedented turnout,”. Read More

Iran’s Only Empress Had A Crown With 1,469 Diamonds & Wedding Dress Designed By Yves Saint Laurent

Created for Empress Farah Pahlavi’s historic 1967 coronation, the dazzling crown was built under extraordinary secrecy using Iran’s legendary treasury gems. Read More

Gemini Horoscope Tomorrow, March 05, 2026: The Day Brings Recognition And Profitable Partnerships

Gemini Horoscope: Hello, curious Gemini! Being an air sign, your adaptability, intellect, and rapid wit ensure your world is constantly abuzz with concepts and associations. Read More

Taurus Horoscope Tomorrow, March 05, 2026: Natives Step Into A Phase Of Recognition And Creativity

Taurus Horoscope: Hello, Loyal Taurus! You stand as the unwavering pillar of the zodiac, celebrated for your resolute determination, and an enduring dedication to your most cherished values. Read More

Topics

UAE travel alert: Air Arabia extends flight suspension to March 9, what travellers need to know

Air Arabia Air Arabia has extended the suspension of its flights to and from the UAE until 15:00 (UAE time) on Monday, March 9, 2026, while allowing a limited number of services to operate in coordination with authorities. Read More

Iran postpones Khamenei’s funeral citing anticipated massive crowds

Iran announced that a state funeral for supreme leader Ayatollah Ali Khamenei, which had been planned for Wednesday evening in Tehran, was postponed “in anticipation of unprecedented turnout,”. Read More

Iran’s Only Empress Had A Crown With 1,469 Diamonds & Wedding Dress Designed By Yves Saint Laurent

Created for Empress Farah Pahlavi’s historic 1967 coronation, the dazzling crown was built under extraordinary secrecy using Iran’s legendary treasury gems. Read More

Gemini Horoscope Tomorrow, March 05, 2026: The Day Brings Recognition And Profitable Partnerships

Gemini Horoscope: Hello, curious Gemini! Being an air sign, your adaptability, intellect, and rapid wit ensure your world is constantly abuzz with concepts and associations. Read More

Taurus Horoscope Tomorrow, March 05, 2026: Natives Step Into A Phase Of Recognition And Creativity

Taurus Horoscope: Hello, Loyal Taurus! You stand as the unwavering pillar of the zodiac, celebrated for your resolute determination, and an enduring dedication to your most cherished values. Read More

Aries Horoscope Tomorrow, March 05, 2026: Native Set To Celebrate Family Joy And Professional Success

Aries Horoscope: Welcome to the realm of Aries! As the first sign of the zodiac, you usher in a surge of passionate enthusiasm, an innate pioneering spirit, and an insatiable thirst for fresh experiences. Read More

SA vs NZ LIVE Score, T20 WC Semi-Final: Proteas Set for High-Stakes Showdown With Black Caps

T20 World Cup Semi-Finals: The ICC T20 World Cup 2026 has entered its decisive phase, with the opening semi-final set to begin in a matter of hours. Read More

Latest T20I Rankings: Abhishek Sharma Reigns No.1, Kishan And Bumrah Move Up The Order

Show Quick Read Key points generated by AI, verified by newsroom New Delhi: Abhishek Sharma’s position as the top T20I batter has weakened as Pakistan’s Sahibzada Farhan advanced in the latest ICC Men’s T20I Player rank Read More

Related Articles