Identity

OAuth apps exploited for persistent compromise

Hacking the security. The threat of information leakage and the security of the system. Red open padlock among closed black ones. Close the gap, fix the problem.

Threat actors have been leveraging OAuth apps to ensure persistence within hacked environments, according to Cybernews.

Initial compromise of an email account believed to have been facilitated by a phishing attack was used by attackers to establish illicit mailbox rules and register a nefarious internal app with 'Mail.Read' and 'offline_access' permissions given OAuth tokens, which allowed continued access to the impacted account even after its password was changed, a report from Proofpoint revealed.

"The strategic value of this approach lies in its persistence mechanism: even if the compromised user's credentials are reset or multifactor authentication is enforced, the malicious OAuth applications maintain their authorized access," said researchers.

Organizations detecting suspicious activity have been urged to promptly revoke all client secrets and existing certificates to prevent new token requests. Application registration and all previously given permissions should also be removed, according to researchers, who also recommended the omission of all related service principals.

You can skip this ad in 5 seconds