Threat reportPhishingTL-2026-0173

OAuth Redirect Abuse — Phishing and Malware Delivery to Government Targets via Entra ID and Google Workspace

highMONITORING

OAuth Redirect Abuse (TL-2026-0173), also tracked as OAuth Redirect Abuse, is a high-severity phishing campaign scored CVSS 7.5, first published 2026-03-04. It has no confirmed attribution, affects Microsoft Entra ID (Azure AD), maps to 23 MITRE ATT&CK techniques (T1016, T1027, T1027.013), and is covered by 9 detection rules and 20 indicators of compromise.

CVSS
7.5/10High
CVEs
0None referenced
Techniques
23MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-0173

Threat ID
TL-2026-0173
Also known as
OAuth Redirect Abuse, Silent OAuth Probe
Severity
HIGH
CVSS
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N)
Status
MONITORING
Category
PHISHING
First published
Last reviewed
Attribution confidence
NONE
Motivation
ESPIONAGE
Target sectors
Government, Public Sector
Target regions
Global
Detection rules
9
Indicators of compromise
20

Malware and tooling in OAuth Redirect Abuse

Malware and tooling: EvilProxy

How OAuth Redirect Abuse works

Microsoft Defender Security Research Team disclosed phishing campaigns that exploit OAuth 2.0's by-design redirect behavior to bypass conventional phishing defenses across email and browser security controls. Multiple threat actors create malicious OAuth applications in actor-controlled tenants with redirect URIs pointing to rogue domains. They distribute phishing links that trigger OAuth authorization flows through Microsoft Entra ID and Google Workspace using intentionally invalid scopes and prompt=none parameters. When silent authentication fails, the identity provider returns an OAuth error and redirects the browser to the attacker's registered redirect URI. Victims are sent to landing pages that deliver ZIP archives containing LNK shortcuts, which execute PowerShell for host reconnaissance, extract payloads via tar, and sideload a malicious DLL (crashhandler.dll) through the legitimate steam_monitor.exe binary. The DLL decrypts crashlog.dat and executes the final payload in memory, establishing C2 connectivity. Some campaigns redirect to EvilProxy adversary-in-the-middle frameworks for credential and session cookie theft. The activity targets government and public-sector organizations using e-signature, Teams recording, social security, financial, and political lure themes.

This campaign represents an identity-based threat class that abuses OAuth's standards-compliant behavior rather than exploiting software vulnerabilities. The attack chain begins with a malicious OAuth application registered in an actor-controlled Azure AD tenant, configured with a redirect URI pointing to attacker infrastructure. Phishing emails distributed via mass-sending tools (both free prebuilt and custom Python/Node.js solutions) contain crafted OAuth authorization URLs targeting the /common/ endpoint for broad tenant coverage.

The OAuth URLs use response_type=code to trigger full authorization flows, prompt=none for silent authentication without UI, and an intentionally invalid scope parameter to guarantee failure. This forces the identity provider into its error-handling path, which by design redirects the browser to the application's registered redirect URI with error parameters (error=interaction_required or error=consent_required). The state parameter, intended for CSRF protection, is repurposed to carry the victim's encoded email address using plaintext, hex, Base64, or custom encoding schemes.

Upon redirect, victims reach attacker-controlled landing pages where ZIP archives are automatically downloaded. The ZIP contains a Windows shortcut (LNK) that executes a PowerShell command upon opening. The PowerShell payload conducts host reconnaissance via ipconfig /all and tasklist, then uses tar to extract three files: steam_monitor.exe (a legitimate Steam binary), crashhandler.dll (the malicious sideloading component), and crashlog.dat (the encrypted final payload).

The legitimate steam_monitor.exe is launched and loads crashhandler.dll from its directory via DLL search-order hijacking. The malicious DLL decrypts crashlog.dat and executes the resulting payload entirely in memory, establishing an outbound connection to external C2 infrastructure. This fileless execution technique evades traditional AV scanning.

Parallel campaigns use the same OAuth redirect mechanism to route victims to EvilProxy and similar adversary-in-the-middle phishing frameworks that intercept credentials and session cookies through proxy-based login interception with CAPTCHA and interstitial obfuscation layers.

Microsoft Entra disabled the observed malicious OAuth applications, but the technique is inherent to OAuth protocol behavior (RFC 6749, RFC 9700 Section 4.11.2) and can be replicated with any OAuth-compliant identity provider. The technique requires no vulnerability exploitation — only application registration and social engineering.

MITRE ATT&CK techniques used in TL-2026-0173

discovery

T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery

defense-evasion

T1027 Obfuscated Files or Information; T1027.013 Encrypted/Encoded File; T1036 Masquerading; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1218.007 Msiexec; T1550.001 Application Access Token

execution

T1059.001 PowerShell; T1204.001 Malicious Link; T1204.002 Malicious File

command-and-control

T1071.001 Web Protocols; T1105 Ingress Tool Transfer

credential-access

T1539 Steal Web Session Cookie

persistence

T1547.001 Registry Run Keys / Startup Folder; T1574.001 DLL

initial-access

T1566.002 Spearphishing Link

resource-development

T1583.006 Web Services; T1585.001 Social Media Accounts; T1608.005 Link Target

reconnaissance

T1598.003 Spearphishing Link

Affected products and versions in OAuth Redirect Abuse

  • Microsoft — Entra ID (Azure AD)
    Vulnerable versions: All — by-design OAuth behavior
    Fixed in: N/A — protocol-level abuse
  • Google — Google Workspace OAuth
    Vulnerable versions: All — by-design OAuth behavior
    Fixed in: N/A — protocol-level abuse

Remediation for OAuth Redirect Abuse

Immediate actions

  • Restrict user consent for OAuth applications — require admin approval for all new app registrations
  • Review and remove unused or overprivileged OAuth application permissions in Entra ID
  • Block or alert on OAuth authorization URLs containing scope=invalid or anomalous scope parameters at proxy/email gateway
  • Enable Conditional Access policies requiring MFA and compliant devices for OAuth authorization flows
  • Hunt for recent ZIP downloads originating from OAuth error redirect URLs (FileOriginUrl containing error=consent_required)

Longer-term hardening

  • Deploy cross-domain XDR detection spanning email, identity, and endpoint signals
  • Implement application governance policies with automated revocation of suspicious OAuth apps
  • Monitor for DLL sideloading via steam_monitor.exe or similar legitimate binaries from non-standard paths
  • Establish OAuth application allowlisting and block third-party app consent by default
  • Conduct periodic OAuth application audit across all tenants to identify rogue redirect URIs

Weaknesses (CWE) in OAuth Redirect Abuse

CWE-601

Timeline of OAuth Redirect Abuse

  • Earliest observed phishing campaigns exploiting OAuth redirect abuse targeting government organizations
  • ZIP payload delivery via OAuth error redirects confirmed with DLL sideloading chain (steam_monitor.exe + crashhandler.dll)
  • Parallel campaigns identified routing OAuth redirects to EvilProxy AitM framework for credential and session theft
  • Microsoft Entra disables identified malicious OAuth applications; notes related activity persists
  • Microsoft Defender Security Research Team publishes detailed analysis of OAuth redirection abuse techniques
  • Threadlinqs Intelligence ingests TL-2026-0173 for full pipeline analysis
  • Microsoft cites RFC 9700 Section 4.11.2 documenting authorization server open redirector risk as standards-compliant behavior
  • The Hacker News publishes coverage of Microsoft OAuth redirect abuse advisory
  • As of 2026-05-29, this OAuth redirect-abuse phishing/malware campaign remains active: it exploits by-design OAuth behavior (RFC 9700, CWE-601, no CVE/patch possible), so Microsoft Entra disabling the observed malicious apps only contained instances. Multiple sources (Microsoft, The Register, Help Net Security, Malwarebytes) confirm related activity persists with no actor disruption or successor.

Sources cited for OAuth Redirect Abuse

Detection coverage for TL-2026-0173

As of 2026-03-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0173 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats