Threat actors have been leveraging OAuth apps to ensure persistence within hacked environments, according to Cybernews.Initial compromise of an email account believed to have been facilitated by a phishing attack was used by attackers to establish illicit mailbox rules and register a nefarious internal app with 'Mail.Read' and 'offline_access' permissions given OAuth tokens, which allowed continued access to the impacted account even after its password was changed, a report from Proofpoint revealed."The strategic value of this approach lies in its persistence mechanism: even if the compromised user's credentials are reset or multifactor authentication is enforced, the malicious OAuth applications maintain their authorized access," said researchers.Organizations detecting suspicious activity have been urged to promptly revoke all client secrets and existing certificates to prevent new token requests. Application registration and all previously given permissions should also be removed, according to researchers, who also recommended the omission of all related service principals.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds

