Attackers use legitimate OAuth services as a stepping stone in phishing
Microsoft has uncovered a campaign in which threat actors abuse OAuth redirection for phishing and malware delivery. The attack starts, as usual, with an email containing a lure and a link, but the link points to a legitimate identity provider such as Azure or Google. The parameters are crafted so that authentication deliberately fails and the user is redirected onward to attacker-controlled infrastructure. From there the attack proceeds as an ordinary identity or endpoint compromise. The technique lets attackers slip past security mechanisms that would otherwise block the email, and rotate redirection domains quickly as they are taken down.
What this means for your organisation
The advice to check that a link goes to a known domain stops working when the link genuinely does. Filters built on domain reputation face the same problem. For the organisation this shifts a substantial part of the phishing defence from the mail gateway to what happens after the click: authentication, device control and endpoint detection. Without those, account takeover becomes a matter of time.
Berigo recommends
- Introduce phishing-resistant authentication so a fake login page yields nothing the attacker can use.
- Require an enrolled and managed device for access to company data, not just the right username and password.
- Monitor redirections and outbound traffic to newly registered domains rather than relying on blocking sender domains.
- Update training: the advice is no longer to inspect the domain in the link, but to reach login pages through bookmarks and known entry points.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch