News: Kaspersky Uncovers Phishing Campaign Weaponizing Microsoft OAuth Authentication Mechanism

News: Kaspersky Uncovers Phishing Campaign Weaponizing Microsoft OAuth Authentication Mechanism



Cybersecurity firm Kaspersky has issued a serious warning regarding an sophisticated phishing campaign that systematically abuses Microsoft’s legitimate authentication infrastructure. 

Spanning from early April to mid-May 2026, the targeted operation saw cybercriminals masquerading as reputable law firms sending password-protected PDF attachments to lure enterprise victims into yielding full control of their Microsoft 365 environments.

The sophisticated threat vector explicitly targets the OAuth 2.0 Device Authorization Grant—a feature designed to simplify logins on input-limited devices like smart TVs. 

Recommended for You

Attackers tricked victims into entering a pre-generated one-time code on Microsoft’s authentic login portal. Once the user completed the multi-factor authentication (MFA) prompt, the threat actors harvested valid session refresh tokens, granting them persistent, unauthorized access to corporate mailboxes, sensitive OneDrive cloud files, and internal Teams communications.

"Threat actors don’t always rely on harvesting credentials or deploying malware to access sensitive data – they can weaponise legitimate tools. 

Therefore, users must exercise vigilance not only when visiting suspicious sites, but also when navigating official platforms. 

We advise enterprise teams to evaluate the business necessity of the Device Code Flow within their corporate infrastructure. If this authentication mechanism is not required for daily operations, it should be disabled."

#Cybersecurity #Kaspersky #Microsoft365 #PhishingAlert #OAuth #DataPrivacy #InfoSec



Latest News


Post a Comment

Previous Post Next Post