Microsoft Warns Governments of Malware Spread via OAuth Redirect Abuse
Mar 3, 2026 // 13:35 - Norina Velotta


Microsoft has warned of phishing campaigns specifically targeting government and public-sector organizations by abusing OAuth redirection mechanisms to deliver malware.

Key Details of the Campaign

  • Targeting: The activity primarily focuses on government and public-sector entities.
  • Mechanism: Attackers exploit the legitimate, “by-design” behavior of OAuth that allows identity providers (like Microsoft Entra ID or Google Workspace) to redirect users to specific pages during error scenarios.
  • Exploitation Method: By crafting URLs with manipulated parameters, attackers force an error code during sign-in. This error triggers a redirect to an attacker-controlled landing page, bypassing traditional security filters that trust identity provider domains.
  • Payload Delivery: Unlike typical OAuth attacks, the goal is often malware delivery rather than token theft. Observed payloads include:
    • ZIP archives containing malicious LNK shortcut files.
    • HTML smuggling loaders.
    • Reconnaissance via PowerShell commands followed by DLL side-loading (e.g., using steam_monitor.exe to load a malicious crashhandler.dll).
  • Phishing Lures: Emails use themes like e-signature requests, Microsoft 365 password resets, and political themes to trick users into clicking the malicious OAuth links.

Mitigation and Status

Microsoft has disabled the identified malicious OAuth applications, but warns that related activity persists and requires ongoing monitoring. Defenders are encouraged to tighten consent policies and block risky OAuth flows.

#abuse  #governments  #malware  #microsoft  #news  #oauth  #redirect  #spread  #via  #warns   —   News