Microsoft cautions about rising risks: Cyber actors exploiting OAuth apps for unauthorized access & malicious activities. Stay vigilant! (IT World Canada)


December 19, 2023

Microsoft has highlighted a concerning trend where malicious actors are exploiting OAuth-based applications as an automated means of authentication, leading to potential security breaches. According to a recent blog post by the tech giant, threat actors are manipulating user accounts to manipulate OAuth applications, granting them significant privileges that can be abused to conceal malicious activities.

By compromising user accounts through tactics like phishing or password spraying, attackers gain access to accounts lacking robust authentication measures. Once inside, they target accounts with permissions to create or modify OAuth applications. Exploiting these applications with elevated permissions allows threat actors to engage in various nefarious activities, including deploying virtual machines for cryptocurrency mining, establishing persistence post-business email compromise, and initiating spamming operations using the victimized organization's resources and domain name.

To combat this growing threat, IT managers are advised to adopt several security measures. These include reinforcing account credentials by implementing multifactor authentication, thereby significantly reducing the vulnerability to attacks, as suggested by Microsoft. Additionally, enabling conditional risk-based access policies can thwart attacks utilizing stolen credentials. Continuous access evaluation, where available, should also be enabled in the environment. IT managers are further urged to activate all security defaults within identity platforms and conduct thorough audits of apps and consented permissions to ensure they only access necessary data and adhere to the principle of least privilege access.

In a detailed report, Microsoft outlined the actions of a specific threat actor, identified as Storm-1283 under their new naming classification. This group utilized a compromised user account to create an OAuth application, subsequently using it to deploy virtual machines for cryptocurrency mining. Leveraging the compromised account, the attacker logged in through a VPN, created a new single-tenant OAuth application within Microsoft Entra ID, giving it a name similar to the tenant domain name. The attacker then added a set of secrets to the application, allowing unauthorized access and exploitation of the system.

Microsoft's findings underscore the critical need for heightened security measures and vigilance against OAuth abuse to prevent such unauthorized access and potential security breaches.

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

You may also like

Google developing 'AI Replies' feature for Pixel Phone app

Google is reportedly working on a new "AI Replies" feature for its Phone app on Pixel smartphones, which will use....

Amazon wins FAA approval for new delivery drone, testing in Arizona

Amazon announced on Tuesday that it received regulatory approval from the Federal Aviation Administration (FAA) to begin flying a new,....

Apple is set to release new AI features for the holiday season

Apple has officially launched its much-anticipated generative AI software, Apple Intelligence, with the first set of features going live on....

Perplexity launches AI-based hub for election information

Perplexity, an innovative company specializing in AI search technology, has introduced a new platform designed to provide essential information to....

Chinese researchers create AI model for military using Meta's Llama

Chinese research institutions tied to the People's Liberation Army (PLA) have reportedly developed a military-focused AI tool using Meta's publicly....

OpenAI partners with Broadcom and TSMC to create new chip

OpenAI is making significant strides in its efforts to enhance its artificial intelligence capabilities by collaborating with Broadcom and TSMC....

Meta creates AI search tool to reduce dependence on Google, Bing

Meta Platforms is making significant strides in the artificial intelligence (AI) sector by developing its own AI-powered search engine, aiming....

Google Developing AI to Take Control of Computers, Says Report

Google is making strides in artificial intelligence with a new project aimed at transforming how we interact with web browsers.....

OpenAI set to launch new AI model Orion by December

OpenAI is gearing up to release its highly anticipated AI model, Orion, sometime in December. However, unlike previous versions like....

Nvidia unveils Hindi AI model to boost growth for Indian firms

Nvidia, a global leader in chip technology, has introduced a new, lightweight AI model designed specifically for Hindi, India’s most....

Google Chrome update introduces article reading feature for users

Google has rolled out a major update to its Chrome browser on Android, significantly enhancing the "Listen to this page"....

Anthropic launches AI tool to automate mouse clicks for coders

Anthropic, a startup backed by Alphabet and Amazon, has introduced updated artificial intelligence models, adding a feature designed to automate....