Wednesday, March 4, 2026
31.1 C
New Delhi

Microsoft Flags New OAuth-Based Phishing Attack Targeting Public Sector

Show Quick Read

Key points generated by AI, verified by newsroom

A new phishing campaign has been discovered that uses a clever trick inside the OAuth login system. Security researchers from Microsoft Defender say attackers are abusing the normal redirection feature of OAuth to send users to malicious websites. Unlike traditional phishing attacks that try to steal passwords or tokens directly, this method works differently. It triggers an error in the authentication process, so the system automatically redirects the victim’s browser. 

The campaign mainly targets government and public-sector organisations. Because the links use trusted identity provider domains, many security filters fail to detect the attack easily.

New OAuth Phishing Attack Uses Redirect Trick

This new OAuth phishing attack works by abusing the normal error-handling process defined in the OAuth standard. Attackers first register fake applications inside their own cloud tenants. They then configure redirect links that lead to domains they control.

Phishing emails are sent with special OAuth authorisation links. These links target the Microsoft Entra ID login endpoint and include parameters designed to break the login process. For example, attackers request an invalid permission, so the authentication attempt fails.

When the request fails, the identity system automatically redirects the browser to the attacker’s registered redirect link. Since this redirect is part of normal OAuth behaviour, many email and browser security systems do not block it.

Five-Stage Phishing Attack Chain Explained

Researchers say the campaign follows a five-stage phishing attack chain. First, attackers send phishing emails related to e-signatures, financial documents, or meeting invites. Automated tools help them send large numbers of messages.

Second, clicking the link triggers a silent OAuth check. The link may also contain the victim’s encoded email address.

Third, the authentication request fails, and the system redirects the user to the attacker’s website. Fourth, victims may be taken to phishing pages or prompted to download malicious ZIP files.

Finally, malware can run PowerShell commands, collect system information, and connect to attacker-controlled servers.

Go to Source

Hot this week

Russian shadow fleet LNG tanker sinks after ‘sudden explosions’ off Libya coast

A Russian liquefied natural gas (LNG) carrier, the Arctic Metagaz, has sunk in the central Mediterranean between Libya and Malta after a “sudden explosion” triggered a massive blaze on board, Libya’s ports and maritime tra Read More

Did UK minister hold a minute’s silence after Khamenei’s death? The misinformation war amid Iran conflict

An image showing Britain’s Home Secretary Shabana Mahmood reportedly holding a minute’s silence for Iran’s Ayatollah Ali Khamenei’s death has gone viral online. Read More

US-Israel Conflict With Iran Enters Fifth Day As Fighting Engulfs Lebanon And Gulf: What We Know

The war has rapidly expanded beyond Iran’s borders, drawing in Lebanon, roiling Gulf states and sparking an intense political battle in Washington. Read More

Iranian Warship Sinks Off Sri Lanka: Over 100 Missing, 78 Injured After Suspected Submarine Attack

The 180-strong crew was aboard the vessel when it began taking on water at dawn, according to local media reports. Read More

Majestic To Ramanagara, Banashankari To Kanakapura: BMTC Launches New AC Routes

For those living along the highway, the buses stop at several major intersections. This “city-style” stopping pattern is what differentiates BMTC service from KSRTC long routes. Read More

Topics

Russian shadow fleet LNG tanker sinks after ‘sudden explosions’ off Libya coast

A Russian liquefied natural gas (LNG) carrier, the Arctic Metagaz, has sunk in the central Mediterranean between Libya and Malta after a “sudden explosion” triggered a massive blaze on board, Libya’s ports and maritime tra Read More

Did UK minister hold a minute’s silence after Khamenei’s death? The misinformation war amid Iran conflict

An image showing Britain’s Home Secretary Shabana Mahmood reportedly holding a minute’s silence for Iran’s Ayatollah Ali Khamenei’s death has gone viral online. Read More

US-Israel Conflict With Iran Enters Fifth Day As Fighting Engulfs Lebanon And Gulf: What We Know

The war has rapidly expanded beyond Iran’s borders, drawing in Lebanon, roiling Gulf states and sparking an intense political battle in Washington. Read More

Iranian Warship Sinks Off Sri Lanka: Over 100 Missing, 78 Injured After Suspected Submarine Attack

The 180-strong crew was aboard the vessel when it began taking on water at dawn, according to local media reports. Read More

Majestic To Ramanagara, Banashankari To Kanakapura: BMTC Launches New AC Routes

For those living along the highway, the buses stop at several major intersections. This “city-style” stopping pattern is what differentiates BMTC service from KSRTC long routes. Read More

Jim Carrey’s publicist confirms he attended 2026 César Awards

Jim Carrey’s publicist has addressed viral conspiracy theories claiming the actor used a body double or clone during a recent awards appearance in Paris. Read More

T20 World Cup 2026: 3 ICC Semi-Final Rules That Could Impact India And New Zealand

ICC Men’s T20 World Cup 2026 has entered its decisive final week, with just three matches left to crown the new champions of T20 cricket. The title race is now down to four teams – South Africa, England, India, and New Zealand. Read More

South Africa vs New Zealand T20 World Cup: Who Qualifies If Rain Washes Out Semi-Final

Show Quick Read Key points generated by AI, verified by newsroom T20 World Cup Semi-Final: South Africa vs New Zealand marks the first of the two ICC T20 World Cup 2026 semi-finals. Read More

Related Articles