Microsoft cautions about rising risks: Cyber actors exploiting OAuth apps for unauthorized access & malicious activities. Stay vigilant! (IT World Canada)


December 19, 2023

Microsoft has highlighted a concerning trend where malicious actors are exploiting OAuth-based applications as an automated means of authentication, leading to potential security breaches. According to a recent blog post by the tech giant, threat actors are manipulating user accounts to manipulate OAuth applications, granting them significant privileges that can be abused to conceal malicious activities.

By compromising user accounts through tactics like phishing or password spraying, attackers gain access to accounts lacking robust authentication measures. Once inside, they target accounts with permissions to create or modify OAuth applications. Exploiting these applications with elevated permissions allows threat actors to engage in various nefarious activities, including deploying virtual machines for cryptocurrency mining, establishing persistence post-business email compromise, and initiating spamming operations using the victimized organization's resources and domain name.

To combat this growing threat, IT managers are advised to adopt several security measures. These include reinforcing account credentials by implementing multifactor authentication, thereby significantly reducing the vulnerability to attacks, as suggested by Microsoft. Additionally, enabling conditional risk-based access policies can thwart attacks utilizing stolen credentials. Continuous access evaluation, where available, should also be enabled in the environment. IT managers are further urged to activate all security defaults within identity platforms and conduct thorough audits of apps and consented permissions to ensure they only access necessary data and adhere to the principle of least privilege access.

In a detailed report, Microsoft outlined the actions of a specific threat actor, identified as Storm-1283 under their new naming classification. This group utilized a compromised user account to create an OAuth application, subsequently using it to deploy virtual machines for cryptocurrency mining. Leveraging the compromised account, the attacker logged in through a VPN, created a new single-tenant OAuth application within Microsoft Entra ID, giving it a name similar to the tenant domain name. The attacker then added a set of secrets to the application, allowing unauthorized access and exploitation of the system.

Microsoft's findings underscore the critical need for heightened security measures and vigilance against OAuth abuse to prevent such unauthorized access and potential security breaches.

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

You may also like

The Onion Eyes Infowars Takeover Deal

A surprising development is unfolding in the ongoing legal and financial battle surrounding Infowars, as satirical outlet The Onion moves....

Artemis II Mission Ends in Dramatic Splashdown, Marking Historic Return to Lunar Exploration

The Artemis II mission concluded with a dramatic splashdown in the Pacific Ocean, bringing home the first crewed lunar journey....

Artemis II Astronauts Break Apollo 13 Record, Emotional Moment Follows Historic Milestone

The Artemis II astronauts marked a historic achievement in space exploration, surpassing the distance record set by Apollo 13, in....

Artemis II Moon Mission Launch Marks Historic Return to Deep Space Exploration

The Artemis II moon mission has successfully launched from Florida, sending four astronauts on a landmark journey around the moon....

Musk Plans to Build ‘Terafab’ Chip Factories in Austin

Elon Musk has revealed ambitious plans to build a next-generation chip manufacturing hub in Texas, signaling a major push to....

NASA Clears Artemis II Moon Mission for April Launch

NASA has cleared its powerful Space Launch System rocket for an April launch, paving the way for humanity’s first crewed....

Meta Buys AI Bot Network Moltbook

Meta Platforms has acquired Moltbook, a newly launched social network where artificial intelligence agents interact with one another autonomously. The....

Robot Boom Ahead? Canadian Firm Eyes AI Factory Future

The race to build smarter, more capable humanoid robots is heating up worldwide, and a small Canadian company believes it....

Cheap Laptops Challenge MacBook Neo With More Storage and Memory

Apple has stepped into the budget laptop segment with the launch of the MacBook Neo, priced at $599. On paper,....

Apple iPhone 17e Leads Apple Product Launch Week With M4 iPad Air Update

Apple has kicked off a fresh round of hardware announcements with a clear focus on value and performance. The company....

Viral AI Caricature Trend Sparks Serious Privacy Fears, Expert Warns

A viral social media trend that turns personal details into AI-generated caricatures is raising red flags among cybersecurity experts, who....

India AI Impact Summit 2026: Global Leaders, CEOs Gather in New Delhi for High-Stakes Talks

India has opened a major global gathering focused on artificial intelligence and its growing worldwide influence. The India AI Impact....