PULSE NAME
OAuth redirection abuse enables phishing and malware delivery
WHITE AlienVault 2026-03-02 Modified: 2026-03-03
4
IOCs
LOW VOLUME
Microsoft has discovered phishing campaigns exploiting OAuth's redirection mechanisms to bypass conventional defenses. Attackers create malicious applications with redirect URIs pointing to malicious domains, then distribute phishing links prompting targets to authenticate. The attack abuses OAuth's error handling to redirect users from trusted providers to attacker-controlled sites for phishing or malware delivery. Campaigns targeted government and public sectors using e-signature, financial, and political lures. Some attacks led to malware downloads and endpoint compromise via PowerShell and DLL side-loading. Mitigation involves governing OAuth apps, limiting user consent, reviewing permissions, and implementing cross-domain detection across email, identity, and endpoint.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
EvilProxy
Indicators of Compromise (4)
All domain hostname
TYPEINDICATORDESCRIPTIONCREATED
domain abv-abc3.top 2026-03-02
domain calltask.im 2026-03-02
domain ouviraparelhosauditivos.com.br 2026-03-02
hostname weds101.siriusmarine-sg.com 2026-03-02