Researchers demonstrated a post-compromise technique that abuses sideloaded AppX packages and the Microsoft-signed WWAHost.exe Windows Web App Host process to steal Microsoft 365 OAuth tokens. On Windows devices where Developer Mode or enterprise sideloading is enabled, an unprivileged user can register an AppX manifest granting attacker-hosted JavaScript unrestricted Windows Runtime access through WindowsRuntimeAccess="all". The chain invokes the legacy WebAuthenticationBroker API to display a legitimate Microsoft sign-in and MFA prompt, intercepts the returned authorization code, and exchanges it for Microsoft 365 access and refresh tokens.
The technique was tested on Windows 11 24H2 against an MFA-protected Entra ID tenant and obtained broad delegated Microsoft Graph permissions using a Microsoft Office client ID. Defenders should investigate outbound connections using the legacy MSAppHost/3.0 user agent to non-Microsoft destinations, alongside AppX registration, manifest, and related endpoint telemetry. Recommended mitigations include restricting Developer Mode and enterprise sideloading, applying Conditional Access and Token Protection where available, enabling Continuous Access Evaluation, and reducing refresh-token persistence.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Huntress disclosed and demonstrated an OAuth token-theft technique in which a sideloaded AppX package uses Microsoft-signed WWAHost.exe and WebAuthenticationBroker to capture a victim's authorization code after legitimate Microsoft sign-in and MFA. The captured code can be exchanged for Microsoft 365 access and refresh tokens, with the latter reportedly reusable from another machine and network without a new MFA prompt.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.