Tuesday, April 21, 2026
38.1 C
New Delhi

Microsoft Flags New OAuth-Based Phishing Attack Targeting Public Sector

Show Quick Read

Key points generated by AI, verified by newsroom

A new phishing campaign has been discovered that uses a clever trick inside the OAuth login system. Security researchers from Microsoft Defender say attackers are abusing the normal redirection feature of OAuth to send users to malicious websites. Unlike traditional phishing attacks that try to steal passwords or tokens directly, this method works differently. It triggers an error in the authentication process, so the system automatically redirects the victim’s browser. 

The campaign mainly targets government and public-sector organisations. Because the links use trusted identity provider domains, many security filters fail to detect the attack easily.

New OAuth Phishing Attack Uses Redirect Trick

This new OAuth phishing attack works by abusing the normal error-handling process defined in the OAuth standard. Attackers first register fake applications inside their own cloud tenants. They then configure redirect links that lead to domains they control.

Phishing emails are sent with special OAuth authorisation links. These links target the Microsoft Entra ID login endpoint and include parameters designed to break the login process. For example, attackers request an invalid permission, so the authentication attempt fails.

When the request fails, the identity system automatically redirects the browser to the attacker’s registered redirect link. Since this redirect is part of normal OAuth behaviour, many email and browser security systems do not block it.

Five-Stage Phishing Attack Chain Explained

Researchers say the campaign follows a five-stage phishing attack chain. First, attackers send phishing emails related to e-signatures, financial documents, or meeting invites. Automated tools help them send large numbers of messages.

Second, clicking the link triggers a silent OAuth check. The link may also contain the victim’s encoded email address.

Third, the authentication request fails, and the system redirects the user to the attacker’s website. Fourth, victims may be taken to phishing pages or prompted to download malicious ZIP files.

Finally, malware can run PowerShell commands, collect system information, and connect to attacker-controlled servers.

Go to Source

Hot this week

West Bengal Elections 2026: Key Highlights Of The Campaign

West Bengal Elections 2026: The poll campaigns intensify as PM Modi and CM Mamata hold rival rallies, TMC and BJP trade charges over identity politics, welfare and law and order. Read More

‘Dhurandhar 2’ BO day 34 [LIVE]: Ranveer Singh film needs Rs. 116 crore to beat ‘Pushpa 2’

The Aditya Dhar directorial ‘Dhurandhar 2: The Revenge’ continues to rewrite history at the global box office. Read More

D4vd charged with Celeste Rivas Hernandez murder: Full timeline

The music world is reeling as alt-pop artist D4vd, real name David Burke, confronts grave accusations, including murder and child sexual abuse, related to the heartbreaking death of 14-year-old Celeste Rivas Hernandez. Read More

‘Felt political pressure’: Sacked official blames Starmer’s office over Mandelson appointment

Britain’s Prime Minister Keir Starmer leaves 10 Downing Street in London, Monday, April 20, 2026 to face a showdown in Parliament over the appointment of Peter Mandelson as ambassador to Washington. Read More

EU expects approval of €90 billion loan for Ukraine tomorrow

European Union foreign policy chief Kaja Kallas has expressed optimism regarding the approval of a €90 billion loan for Ukraine, with a decision expected this Wednesday. Read More

Topics

West Bengal Elections 2026: Key Highlights Of The Campaign

West Bengal Elections 2026: The poll campaigns intensify as PM Modi and CM Mamata hold rival rallies, TMC and BJP trade charges over identity politics, welfare and law and order. Read More

‘Dhurandhar 2’ BO day 34 [LIVE]: Ranveer Singh film needs Rs. 116 crore to beat ‘Pushpa 2’

The Aditya Dhar directorial ‘Dhurandhar 2: The Revenge’ continues to rewrite history at the global box office. Read More

D4vd charged with Celeste Rivas Hernandez murder: Full timeline

The music world is reeling as alt-pop artist D4vd, real name David Burke, confronts grave accusations, including murder and child sexual abuse, related to the heartbreaking death of 14-year-old Celeste Rivas Hernandez. Read More

‘Felt political pressure’: Sacked official blames Starmer’s office over Mandelson appointment

Britain’s Prime Minister Keir Starmer leaves 10 Downing Street in London, Monday, April 20, 2026 to face a showdown in Parliament over the appointment of Peter Mandelson as ambassador to Washington. Read More

EU expects approval of €90 billion loan for Ukraine tomorrow

European Union foreign policy chief Kaja Kallas has expressed optimism regarding the approval of a €90 billion loan for Ukraine, with a decision expected this Wednesday. Read More

Two arrested for planning terror attacks in Delhi-NCR; recruited by ISI proxy Shahzad Bhatti

Pakistan-based gangster and ISI proxy Shahzad Bhatti (right) NEW DELHI: The Special Cell of Delhi Police has arrested two individuals allegedly connected to Pakistan-based gangster and ISI proxy Shahzad Bhatti. Read More

Buyback Tax Rules Shift Again: What It Means As Wipro Rolls Out Rs 15,000 Crore Offer

Show Quick Read Key points generated by AI, verified by newsroom Wipro announces massive Rs 15,000 crore share buyback. Buyback tax shifts to capital gains from April 2026. Tax applies only to actual profit, not full amount. Read More

Sai Abhyankkar clarifies replacing AR Rahman in ‘Karuppu’

Young composer Sai Abhyankkar has finally addressed the much-talked-about change in the music department of Karuppu, which stars Suriya. The film, directed by RJ Balaji, was initially set to have music by A. R. Rahman. Read More

Related Articles