Tuesday, April 21, 2026
38.1 C
New Delhi

Microsoft Flags New OAuth-Based Phishing Attack Targeting Public Sector

Show Quick Read

Key points generated by AI, verified by newsroom

A new phishing campaign has been discovered that uses a clever trick inside the OAuth login system. Security researchers from Microsoft Defender say attackers are abusing the normal redirection feature of OAuth to send users to malicious websites. Unlike traditional phishing attacks that try to steal passwords or tokens directly, this method works differently. It triggers an error in the authentication process, so the system automatically redirects the victim’s browser. 

The campaign mainly targets government and public-sector organisations. Because the links use trusted identity provider domains, many security filters fail to detect the attack easily.

New OAuth Phishing Attack Uses Redirect Trick

This new OAuth phishing attack works by abusing the normal error-handling process defined in the OAuth standard. Attackers first register fake applications inside their own cloud tenants. They then configure redirect links that lead to domains they control.

Phishing emails are sent with special OAuth authorisation links. These links target the Microsoft Entra ID login endpoint and include parameters designed to break the login process. For example, attackers request an invalid permission, so the authentication attempt fails.

When the request fails, the identity system automatically redirects the browser to the attacker’s registered redirect link. Since this redirect is part of normal OAuth behaviour, many email and browser security systems do not block it.

Five-Stage Phishing Attack Chain Explained

Researchers say the campaign follows a five-stage phishing attack chain. First, attackers send phishing emails related to e-signatures, financial documents, or meeting invites. Automated tools help them send large numbers of messages.

Second, clicking the link triggers a silent OAuth check. The link may also contain the victim’s encoded email address.

Third, the authentication request fails, and the system redirects the user to the attacker’s website. Fourth, victims may be taken to phishing pages or prompted to download malicious ZIP files.

Finally, malware can run PowerShell commands, collect system information, and connect to attacker-controlled servers.

Go to Source

Hot this week

Viswanathan Anand relates to Magnus Carlsen as he discusses World No 1 relinquishing world chess title: ‘I was getting bored’

Chess great Viswanathan Anand has finally broken his silence on Magnus Carlsen relinquishing the world chess title in 2022, speaking about the similarities between how he felt and what the world No 1 must have experienced. Read More

Pakistan Extends Airspace Ban For Indian Aircrafts Till May 24

Pakistan extends its airspace ban on Indian aircraft to May 24 covering Karachi and Lahore regions after the Pahalgam attack. Read More

Dozens Of US Military Veterans Arrested Protesting Iran War At Capitol Hill

The veterans gathered inside the rotunda of the Cannon House Office Building at Capitol Hill, many dressed in military fatigues. Read More

Mandelson Row: Top Civil Servant Puts Starmer Under Pressure Over Sacked Envoy’s Epstein Links

Sacked official Olly Robbins told a parliamentary panel there was “pressure” to appoint Mandelson, amid scrutiny over vetting and Epstein ties. Read More

Topics

Viswanathan Anand relates to Magnus Carlsen as he discusses World No 1 relinquishing world chess title: ‘I was getting bored’

Chess great Viswanathan Anand has finally broken his silence on Magnus Carlsen relinquishing the world chess title in 2022, speaking about the similarities between how he felt and what the world No 1 must have experienced. Read More

Pakistan Extends Airspace Ban For Indian Aircrafts Till May 24

Pakistan extends its airspace ban on Indian aircraft to May 24 covering Karachi and Lahore regions after the Pahalgam attack. Read More

Dozens Of US Military Veterans Arrested Protesting Iran War At Capitol Hill

The veterans gathered inside the rotunda of the Cannon House Office Building at Capitol Hill, many dressed in military fatigues. Read More

Mandelson Row: Top Civil Servant Puts Starmer Under Pressure Over Sacked Envoy’s Epstein Links

Sacked official Olly Robbins told a parliamentary panel there was “pressure” to appoint Mandelson, amid scrutiny over vetting and Epstein ties. Read More

Trump Says Iran Breached Ceasefire Multiple Times As Islamabad Peace Talks Window Closes

Posting on his social media platform Truth Social, Trump alleged repeated Iranian breaches of the temporary truce that had paused weeks of hostilities in West Asia. Read More

How Much Is Iran War Costing And How Many Lives Could That Money Have Saved Instead?

Tom Fletcher, who heads the UN humanitarian agency, said around $2 billion is being spent for every day the conflict continues. Read More

Genelia Deshmukh’s Soft Pink Nauvari Is A Love Letter To Marathi Heritage

Genelia donned a bespoke soft pink Nauvari saree from Ryree by Shreya Deshmukh. Read More

Related Articles