Microsoft says criminals are misusing OAuth apps to launch scam attacks

microsoft, microsoft says criminals are misusing oauth apps to launch scam attacks

Kryptovaluuttojen louhinta on tehokkainta oikeilla komponenteilla.

Microsoft says its Threat Intelligence team has been observing financially motivated attacks and scams using OAuth apps as automation tools.

In a new post, the team explained how threat actors have compromised user accounts to create, modify, and grant high privileges to OAuth apps to hide malicious activity.

Fortunately, the scale of the attacks has been measured by means of account protection – attackers have been targeting user accounts without strong authentication mechanisms – which at least gives users and admins some hope to apply further protection against the scams.

Is your account securely protected?

Microsoft said that threat actors mostly launched their attacks via phishing or password spraying methods. They then went on to misuse OAuth apps with high privilege permissions for a variety of reasons.

A group tracked as Storm-1283 (the Storm prefix suggests that this is currently a low-scale group that’s in developed rather than a long-standing threat actor) was caught signing in via a VPN and creating a new single-tenant OAuth app in Microsoft Entra ID. The group then deployed VMs for crypto mining.

Organizations targeted in this way by Storm-1283 had racked up compute fees ranging from $10,000 to $1.5 million, according to Redmond.

Microsoft’s researchers also observed business email compromise and phishing attacks, highlighting some key subject lines to look out for:

  • shared “ contracts” with you.
  • shared “” with you.
  • OneDrive: You have received a new document today
  • Mailbox password expiry
  • Mailbox password expiry
  • You have Encrypted message
  • Encrypted message received

Redmond’s boffins have also drawn up plans to help organizations reduce the likelihood of becoming victims, including implementing security practices such as multi-factor authentication (MFA), enabling conditional access policies, and enabling continuous access evaluation (CAE).

IT workers can refer to Microsoft’s blog post for a full list of mitigation steps and a detailed analysis of the attacks.

More from TechRadar Pro

  • Microsoft lifts the lid on a dangerous new hacking group that could pose a major threat to your online accounts
  • Worried you’ve given too much personal information away? Check out the best identity theft protection
  • Get a security boost with the best firewalls and best endpoint protection
News Related

OTHER NEWS

Jimmy Carter and all living former first ladies to attend Rosalynn Carter’s memorial service

Former President Jimmy Carter is expected to attend the Tuesday memorial service for his late wife, Rosalynn Carter, in Atlanta, his grandson told CNN – a tribute that will also be ... Read more »

Rob Reiner to Film ‘This Is Spinal Tap' Sequel in February, Says Paul McCartney and Elton John Will Appear

Rob Reiner to Film ‘This Is Spinal Tap’ Sequel in February, Says Paul McCartney and Elton John Will Appear Forty years after making his directorial debut with the 1984 cult ... Read more »

Best Buy's Biggest Cyber Monday Deals on Samsung TVs, Sony Headphones, and Dyson Vacuums

Plus laptops and more last-minute deals you don’t want to miss People / Jaclyn Mastropasqua We have reached Cyber Monday is officially here, and there are loads of great deals ... Read more »

The Joffre Lakes surge returns north of Pemberton

The Joffre Lakes surge is back, much to the dismay of Pemberton and Mount Currie locals. Video footage shared with Pique shows a long line of cars illegally parked on ... Read more »

Activists calling for Gaza ceasefire begin hunger strike outside White House

Photograph: Jim Watson/AFP/Getty Images Leftwing activists including the actor Cynthia Nixon, famous for her role in Sex and the City, have begun a hunger strike outside the White House aimed ... Read more »

We just got a first look at McDonald's secretive new spinoff restaurant CosMc's

A construction site in Bolingbrook, Illinois, presumed to be the first location of CosMc’s. Scott Fredrickson McDonald’s has been reluctant to share many details about its planned new restaurant concept ... Read more »

Conor McGregor’s The Black Forge posts more than $2 million in losses since 2021 opening

Conor McGregor’s The Black Forge posts more than $2 million in losses since 2021 opening Conor McGregor made around a $2 million investment when he purchased the Dublin bar he ... Read more »
Top List in the World