Explorer

Microsoft Flags New OAuth-Based Phishing Attack Targeting Public Sector

Security researchers warn about a new phishing campaign abusing OAuth login redirects. The attack tricks identity systems into sending victims to malicious websites, making it harder for many security tools to detect.

Show Quick Read
Key points generated by AI, verified by newsroom
  • New phishing campaign uses OAuth redirection trick.
  • Attackers exploit OAuth errors for malicious redirects.
  • Targets government organizations via trusted identity domains.

A new phishing campaign has been discovered that uses a clever trick inside the OAuth login system. Security researchers from Microsoft Defender say attackers are abusing the normal redirection feature of OAuth to send users to malicious websites. Unlike traditional phishing attacks that try to steal passwords or tokens directly, this method works differently. It triggers an error in the authentication process, so the system automatically redirects the victim’s browser. 

The campaign mainly targets government and public-sector organisations. Because the links use trusted identity provider domains, many security filters fail to detect the attack easily.

New OAuth Phishing Attack Uses Redirect Trick

This new OAuth phishing attack works by abusing the normal error-handling process defined in the OAuth standard. Attackers first register fake applications inside their own cloud tenants. They then configure redirect links that lead to domains they control.

Phishing emails are sent with special OAuth authorisation links. These links target the Microsoft Entra ID login endpoint and include parameters designed to break the login process. For example, attackers request an invalid permission, so the authentication attempt fails.

When the request fails, the identity system automatically redirects the browser to the attacker’s registered redirect link. Since this redirect is part of normal OAuth behaviour, many email and browser security systems do not block it.

Five-Stage Phishing Attack Chain Explained

Researchers say the campaign follows a five-stage phishing attack chain. First, attackers send phishing emails related to e-signatures, financial documents, or meeting invites. Automated tools help them send large numbers of messages.

Second, clicking the link triggers a silent OAuth check. The link may also contain the victim’s encoded email address.

Third, the authentication request fails, and the system redirects the user to the attacker’s website. Fourth, victims may be taken to phishing pages or prompted to download malicious ZIP files.

Finally, malware can run PowerShell commands, collect system information, and connect to attacker-controlled servers.

Frequently Asked Questions

How does this new OAuth phishing campaign work?

Attackers exploit the OAuth redirection feature. They trigger an authentication error, causing the system to redirect victims to malicious websites.

What makes this phishing attack difficult to detect?

The campaign uses trusted identity provider domains in its links. This bypasses many security filters that would normally block suspicious URLs.

What is the typical sequence of events in this five-stage phishing attack?

It involves phishing emails, a silent OAuth check, an authentication failure with redirection, landing on phishing pages or downloading malware, and finally, malware execution.

About the author Annie Sharma

Annie Sharma is a technology journalist at ABP Live English, focused on breaking down complex tech stories into clear, reader-friendly narratives. Gaining hands-on experience in digital storytelling and news writing with leading publications, Annie believes technology should feel accessible rather than overwhelming, and follows a clear, reader-first approach in her work.

For tips and queries, you can reach out to her at annies@abpnetwork.com.

Read More

Top Headlines

Poco M8x 5G Review: Battery That Gives Goals, Pixel That Brings Problems
Poco M8x 5G Review: Battery That Gives Goals, Pixel That Brings Problems
IT Stocks Today: TCS Leads 3.3% Nifty IT Rally As Investors Shrug Off US Green-Card Curbs
Why IT Stocks Are Rising Today: TCS Results Lift Sentiment Despite US Immigration Curbs
Canon Camera Deals On Amazon Right Now: EOS R100 At Rs 44,989, EOS R50 V At Rs 67,990, More
Canon Camera Deals On Amazon Right Now: EOS R100 At Rs 44,989, EOS R50 V At Rs 67,990, More
Beyond Megapixels: How To Read A Camera Spec Sheet During Amazon Great Indian Festival 2026
Beyond Megapixels: How To Read A Camera Spec Sheet During Amazon Great Indian Festival 2026

Videos

Breaking News: CJP Workers Stopped at Itarsi Railway Station, Protest Erupts Over Detention En Route to Delhi
Breaking News: BJP Wins West Bengal's Rejinagar Bypoll by 72,000 Votes in Major Political Upset
Breaking News: Delhi Protest Alert! Train Cancellations, Security Checks and Travel Disruptions Ahead
Breaking News: Congress Camp Reportedly Upset as Uddhav Thackeray Skips INDIA Bloc Protest in Delhi
Breaking News: Supreme Court Takes Up CJP Protest Row as Kapil Sibal Questions Delhi Police Restrictions

Photo Gallery

25°C
New Delhi
Rain: 100mm
Humidity: 97%
Wind: WNW 47km/h
See Today's Weather
powered by
Accu Weather
Embed widget