Security News > 2023 > January > Microsoft disables verified partner accounts used for OAuth phishing
Microsoft has disabled multiple fraudulent, verified Microsoft Partner Network accounts for creating malicious OAuth applications that breached organizations' cloud environments to steal email.
In a joint announcement between Microsoft and Proofpoint, Microsoft says the threat actors posed as legitimate companies to enroll and successfully be verified as that company in the MCPP. The threat actors used these accounts to register verified OAuth apps in Azure AD for consent phishing attacks targeting corporate users in the UK and Ireland.
Microsoft says the malicious OAuth apps were used to steal customers' emails.
Proofpoint disclosed the malicious campaign on December 15, 2022, with Microsoft soon shutting down all fraudulent accounts and OAuth apps.
Over the past few years, malicious threat actors have used OAuth apps in 'consent phishing' attacks to access targeted organizations' Office 365 and Microsoft 365 cloud data.
To further protect customers, Microsoft allows developers to become verified publishers, meaning Microsoft has verified their identity.
News URL
Related news
- Microsoft disrupts ONNX phishing-as-a-service infrastructure (source)
- Phishing-as-a-Service "Rockstar 2FA" Targets Microsoft 365 Users with AiTM Attacks (source)
- New Rockstar 2FA phishing service targets Microsoft 365 accounts (source)
- HubSpot phishing targets 20,000 Microsoft Azure accounts (source)