As cited
Copy frozen at (site build).
Microsoft Entra ID OAuth Phishing and Detections
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Microsoft Entra ID OAuth Phishing and Detections
Elastic's threat research team documented OAuth phishing campaigns targeting Microsoft Entra ID, building on Volexity's investigation of Russian threat actor UTA0352. The researchers emulated two attack chains: one abusing Visual Studio Code (VSCode) to harvest access tokens for Microsoft Graph application programming interface (API), and a second leveraging the Microsoft Authentication Broker with the open-source tool ROADtools to register devices and obtain primary refresh tokens for persistent access. Both scenarios demonstrate how attackers exploit legitimate OAuth flows and first-party Microsoft applications to bypass security controls and access sensitive data like emails and SharePoint sites.
Why it matters: Practitioners defending Microsoft 365 environments need to understand OAuth phishing risks and implement the detection rules for session reuse, suspicious Authentication Broker flows, device registration anomalies, and primary refresh token transitions that Elastic published, as these attacks bypass traditional defenses by abusing trusted applications and token workflows rather than malware or code execution.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Microsoft Entra ID OAuth Phishing and Detections
Elastic's threat research team documented OAuth phishing campaigns targeting Microsoft Entra ID, building on Volexity's investigation of Russian threat actor UTA0352. The researchers emulated two attack chains: one abusing Visual Studio Code (VSCode) to harvest access tokens for Microsoft Graph application programming interface (API), and a second leveraging the Microsoft Authentication Broker with the open-source tool ROADtools to register devices and obtain primary refresh tokens for persistent access. Both scenarios demonstrate how attackers exploit legitimate OAuth flows and first-party Microsoft applications to bypass security controls and access sensitive data like emails and SharePoint sites.
Why it matters: Practitioners defending Microsoft 365 environments need to understand OAuth phishing risks and implement the detection rules for session reuse, suspicious Authentication Broker flows, device registration anomalies, and primary refresh token transitions that Elastic published, as these attacks bypass traditional defenses by abusing trusted applications and token workflows rather than malware or code execution.
- Source published
- First seen by Cybersecurity Tracker