Microsoft reported phishing campaigns targeting government and public-sector organizations that abuse legitimate OAuth redirect behavior in identity providers (including Microsoft Entra ID and Google Workspace) to send victims from seemingly benign authorization URLs to attacker-controlled infrastructure. The technique does not rely on exploiting a software vulnerability or stealing OAuth tokens; instead, attackers register a malicious OAuth application in a tenant they control, then send victims an OAuth link that triggers an error flow (e.g., via an intentionally invalid scope) to force a redirect to a rogue domain hosting malware. Microsoft said the delivered payloads have included ZIP archives that lead to execution chains involving LNK-based execution, PowerShell, and DLL side-loading, consistent with follow-on hands-on-keyboard or pre-ransomware activity.
Microsoft stated it disabled the identified malicious OAuth applications in Entra ID, but warned that related OAuth abuse activity persists and requires continued monitoring. Reported lures used in the phishing emails included e-signature requests, access to Teams meeting recordings, Microsoft 365 password reset instructions, and political themes; Microsoft also observed indicators consistent with the use of free mass-mailing tools and custom tooling (including Python and Node.js) to distribute the campaigns and deliver malware capable of endpoint takeover.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft Defender researchers publicly warned about the campaigns and said the activity abuses standards-compliant OAuth redirect behavior rather than a software vulnerability. Microsoft recommended tighter OAuth app governance, restricting user consent, reviewing and removing risky app permissions, and improving cross-domain detection across email, identity, and endpoints.
During its investigation, Microsoft identified and removed or disabled several malicious OAuth applications used in the campaigns within Microsoft Entra ID. The company noted that related OAuth abuse activity was still continuing and required ongoing monitoring.
Microsoft documented that redirected victims were sent either to adversary-in-the-middle phishing infrastructure such as EvilProxy to steal credentials and session cookies, or to malware-delivery chains. One observed infection path delivered ZIP files with LNK and HTML smuggling components, followed by PowerShell reconnaissance, DLL sideloading via steam_monitor.exe, and an in-memory payload communicating with command-and-control infrastructure.
Threat actors launched ongoing phishing campaigns primarily targeting government and public-sector organizations by abusing legitimate OAuth redirection and error-handling behavior in providers such as Microsoft Entra ID and Google Workspace. The attacks used crafted authorization URLs, including invalid scopes and prompt=none, to redirect victims from trusted identity-provider domains to attacker-controlled infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcehelpnetsecurity.com
Open sourcecsoonline.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.