What’s the matter?
Most Microsoft phishing attacks go after credentials to hijack the accounts. However, researchers have discovered a new phishing campaign that uses Microsoft Office 365 OAuth apps to take over an account.
“This attack method is unique in that it's effectively malware targeting a victim's Office 365 account. It's highly persistent, will completely bypass most traditional defensive measures, and is difficult to detect and remove unless you know what you're looking for. It's really quite clever, and extremely dangerous,” said researchers from PhishLabs.
The details
In case the attack is successful, the attackers will have several permissions in the compromised account including reading emails, contacts, OneNote notebooks, and more.
Guidelines
Here are a few tips that can help you spot malicious OAuth apps.
Publisher