Microsoft Warns OAuth Redirect Abuse Delivers Malware to Government Targets
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内。首先,我得通读整篇文章,抓住主要信息。 文章讲的是微软警告的一种新的网络钓鱼攻击方式。攻击者利用OAuth的重定向机制,通过钓鱼邮件将受害者引导到恶意网站。这种方法不依赖于传统的钓鱼手段,而是利用OAuth的标准功能,让链接看似合法,实则危险。 攻击过程是这样的:攻击者创建一个恶意应用,并设置重定向到托管恶意软件的域名。然后通过钓鱼邮件发送链接,诱导用户点击。一旦用户点击,就会下载恶意软件,导致设备感染。 微软提到这些钓鱼邮件使用了各种诱饵主题,比如电子签名请求、Teams录音等,并且使用了多种工具发送邮件。此外,攻击者还滥用OAuth的状态参数来增加可信度。 最后,微软建议组织限制用户同意权限,并定期审查应用权限。 现在我要把这些信息浓缩到100字以内。重点包括:微软警告、钓鱼攻击、利用OAuth机制、恶意链接、重定向到恶意网站、导致设备感染、建议措施。 确保语言简洁明了,不使用开头的固定句式。 </think> 微软警告称,网络钓鱼攻击利用OAuth重定向机制绕过传统防御措施。攻击者通过钓鱼邮件将用户引导至恶意网站,最终导致设备感染恶意软件。此类攻击针对政府和公共部门组织,并未窃取令牌或利用软件漏洞。建议组织限制用户权限并审查应用权限以应对威胁。 2026-3-3 09:20:0 Author: thehackernews.com(查看原文) 阅读量:7 收藏

Microsoft on Monday warned of phishing campaigns that employ phishing emails and OAuth URL redirection mechanisms to bypass conventional phishing defenses implemented in email and browsers.

The activity, the company said, targets government and public-sector organizations with the end goal of redirecting victims to attacker-controlled infrastructure without stealing their tokens. It described the phishing attacks as an identity-based threat that takes advantage of OAuth's standard, by-design behavior rather than exploiting software vulnerabilities or stealing credentials.

"OAuth includes a legitimate feature that allows identity providers to redirect users to a specific landing page under certain conditions, typically in error scenarios or other defined flows," the Microsoft Defender Security Research Team said.

"Attackers can abuse this native functionality by crafting URLs with popular identity providers, such as Entra ID or Google Workspace, that use manipulated parameters or associated malicious applications to redirect users to attacker-controlled landing pages. This technique enables the creation of URLs that appear benign but ultimately lead to malicious destinations."

The starting point of the attack is a malicious application created by the threat actor in a tenant under their control. The application is configured with a redirect URL pointing to a rogue domain that hosts malware. The attackers then distribute an OAuth phishing link that instructs the recipients to authenticate to the malicious application by using an intentionally invalid scope.

The result of this redirection is that users inadvertently download and infect their own devices with malware. The malicious payloads are distributed in the form of ZIP archives, which, when unpacked, result in PowerShell execution, DLL side-loading, and pre-ransom or hands-on-keyboard activity, Microsoft said.

The ZIP file contains a Windows shortcut (LNK) that executes a PowerShell command as soon as it's opened. The PowerShell payload is used to conduct host reconnaissance by running discovery commands. The LNK file extracts from the ZIP archive an MSI installer, which then drops a decoy document to mislead the victim, while a malicious DLL ("crashhandler.dll") is sideloaded using the legitimate "steam_monitor.exe" binary.

The DLL proceeds to decrypt another file named "crashlog.dat" and executes the final payload in memory, allowing it to establish an outbound connection to an external command-and-control (C2) server.

Microsoft said the emails use e-signature requests, Teams recordings, social security, financial, and political themes as lures to trick users into clicking the link. The emails are said to have been sent via mass-sending tools and custom solutions developed in Python and Node.js. The links are either directly included in the email body or placed within a PDF document.

"To increase credibility, actors passed the target email address through the state parameter using various encoding techniques, allowing it to be automatically populated on the phishing page," Microsoft said. "The state parameter is intended to be randomly generated and used to correlate request and response values, but in these cases it was repurposed to carry encoded email addresses."

While some of the campaigns have been found to leverage the technique to deliver malware, others send users to pages hosted on phishing frameworks such as EvilProxy, which act as an adversary-in-the-middle (AitM) kit to intercept credentials and session cookies.

Microsoft has since removed several malicious OAuth applications that were identified as part of the investigation. Organizations are advised to limit user consent, periodically review application permissions, and remove unused or overprivileged apps.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/03/microsoft-warns-oauth-redirect-abuse.html
如有侵权请联系:admin#unsafe.sh