CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Microsoft Entra ID OAuth Phishing and Detections

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5146

As cited

Copy frozen at (site build).

Microsoft Entra ID OAuth Phishing and Detections

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Microsoft Entra ID OAuth Phishing and Detections

Elastic's threat research team documented OAuth phishing campaigns targeting Microsoft Entra ID, building on Volexity's investigation of Russian threat actor UTA0352. The researchers emulated two attack chains: one abusing Visual Studio Code (VSCode) to harvest access tokens for Microsoft Graph application programming interface (API), and a second leveraging the Microsoft Authentication Broker with the open-source tool ROADtools to register devices and obtain primary refresh tokens for persistent access. Both scenarios demonstrate how attackers exploit legitimate OAuth flows and first-party Microsoft applications to bypass security controls and access sensitive data like emails and SharePoint sites.

Why it matters: Practitioners defending Microsoft 365 environments need to understand OAuth phishing risks and implement the detection rules for session reuse, suspicious Authentication Broker flows, device registration anomalies, and primary refresh token transitions that Elastic published, as these attacks bypass traditional defenses by abusing trusted applications and token workflows rather than malware or code execution.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Microsoft Entra ID OAuth Phishing and Detections

Elastic's threat research team documented OAuth phishing campaigns targeting Microsoft Entra ID, building on Volexity's investigation of Russian threat actor UTA0352. The researchers emulated two attack chains: one abusing Visual Studio Code (VSCode) to harvest access tokens for Microsoft Graph application programming interface (API), and a second leveraging the Microsoft Authentication Broker with the open-source tool ROADtools to register devices and obtain primary refresh tokens for persistent access. Both scenarios demonstrate how attackers exploit legitimate OAuth flows and first-party Microsoft applications to bypass security controls and access sensitive data like emails and SharePoint sites.

Why it matters: Practitioners defending Microsoft 365 environments need to understand OAuth phishing risks and implement the detection rules for session reuse, suspicious Authentication Broker flows, device registration anomalies, and primary refresh token transitions that Elastic published, as these attacks bypass traditional defenses by abusing trusted applications and token workflows rather than malware or code execution.

VendorsMicrosoftAppleElastic
Actorsplay
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary