# OAuth Redirect Abuse — Phishing and Malware Delivery to Government Targets via Entra ID and Google Workspace

> Microsoft Defender Security Research Team disclosed phishing campaigns that exploit OAuth 2.0's by-design redirect behavior to bypass conventional phishing defenses across email and browser security controls. Multiple threat actors create malicious OAuth applications in actor-controlled tenants with redirect URIs pointing to rogue domains. They distribute phishing links that trigger OAuth authorization flows through Microsoft Entra ID and Google Workspace using intentionally invalid scopes and prompt=none parameters. When silent authentication fails, the identity provider returns an OAuth error and redirects the browser to the attacker's registered redirect URI. Victims are sent to landing pages that deliver ZIP archives containing LNK shortcuts, which execute PowerShell for host reconnaissance, extract payloads via tar, and sideload a malicious DLL (crashhandler.dll) through the legitimate steam_monitor.exe binary. The DLL decrypts crashlog.dat and executes the final payload in memory, establishing C2 connectivity. Some campaigns redirect to EvilProxy adversary-in-the-middle frameworks for credential and session cookie theft. The activity targets government and public-sector organizations using e-signature, Teams recording, social security, financial, and political lure themes.

- **Published:** 2026-03-04T00:30:00Z
- **Last reviewed:** 2026-03-04T00:30:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0173
- **ID:** TL-2026-0173
- **Severity:** HIGH (CVSS 7.5)
- **Category:** PHISHING
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

This campaign represents an identity-based threat class that abuses OAuth's standards-compliant behavior rather than exploiting software vulnerabilities. The attack chain begins with a malicious OAuth application registered in an actor-controlled Azure AD tenant, configured with a redirect URI pointing to attacker infrastructure. Phishing emails distributed via mass-sending tools (both free prebuilt and custom Python/Node.js solutions) contain crafted OAuth authorization URLs targeting the /common/ endpoint for broad tenant coverage.

The OAuth URLs use response_type=code to trigger full authorization flows, prompt=none for silent authentication without UI, and an intentionally invalid scope parameter to guarantee failure. This forces the identity provider into its error-handling path, which by design redirects the browser to the application's registered redirect URI with error parameters (error=interaction_required or error=consent_required). The state parameter, intended for CSRF protection, is repurposed to carry the victim's encoded email address using plaintext, hex, Base64, or custom encoding schemes.

Upon redirect, victims reach attacker-controlled landing pages where ZIP archives are automatically downloaded. The ZIP contains a Windows shortcut (LNK) that executes a PowerShell command upon opening. The PowerShell payload conducts host reconnaissance via ipconfig /all and tasklist, then uses tar to extract three files: steam_monitor.exe (a legitimate Steam binary), crashhandler.dll (the malicious sideloading component), and crashlog.dat (the encrypted final payload).

The legitimate steam_monitor.exe is launched and loads crashhandler.dll from its directory via DLL search-order hijacking. The malicious DLL decrypts crashlog.dat and executes the resulting payload entirely in memory, establishing an outbound connection to external C2 infrastructure. This fileless execution technique evades traditional AV scanning.

Parallel campaigns use the same OAuth redirect mechanism to route victims to EvilProxy and similar adversary-in-the-middle phishing frameworks that intercept credentials and session cookies through proxy-based login interception with CAPTCHA and interstitial obfuscation layers.

Microsoft Entra disabled the observed malicious OAuth applications, but the technique is inherent to OAuth protocol behavior (RFC 6749, RFC 9700 Section 4.11.2) and can be replicated with any OAuth-compliant identity provider. The technique requires no vulnerability exploitation — only application registration and social engineering.

## MITRE ATT&CK

- T1566.002 Spearphishing Link
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1059.001 PowerShell
- T1574.001 DLL
- T1036 Masquerading
- T1140 Deobfuscate/Decode Files or Information
- T1027 Obfuscated Files or Information
- T1027.013 Encrypted/Encoded File
- T1082 System Information Discovery
- T1057 Process Discovery
- T1016 System Network Configuration Discovery
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1547.001 Registry Run Keys / Startup Folder
- T1218.007 Msiexec
- T1055 Process Injection
- T1539 Steal Web Session Cookie
- T1550.001 Application Access Token
- T1598.003 Spearphishing Link
- T1583.006 Web Services
- T1608.005 Link Target
- T1585.001 Social Media Accounts

## Sources

- [Microsoft Security Blog — OAuth Redirection Abuse Enables Phishing and Malware Delivery](https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/)
- [The Hacker News — Microsoft Warns OAuth Redirect Abuse Delivers Malware to Government Targets](https://thehackernews.com/2026/03/microsoft-warns-oauth-redirect-abuse.html)
- [RFC 6749 — The OAuth 2.0 Authorization Framework](https://datatracker.ietf.org/doc/html/rfc6749)
- [RFC 9700 — OAuth 2.0 Security Best Current Practice](https://datatracker.ietf.org/doc/html/rfc9700)
- [MITRE ATT&CK — Phishing: Spearphishing Link (T1566.002)](https://attack.mitre.org/techniques/T1566/002/)
- [MITRE ATT&CK — DLL Side-Loading (T1574.002)](https://attack.mitre.org/techniques/T1574/002/)
- [OAuth 2.0 Specification](https://oauth.net/2/)
- [Microsoft Entra ID Documentation — OAuth 2.0 Authorization Code Flow](https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-auth-code-flow)
- [EvilProxy Phishing-as-a-Service Analysis](https://www.resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web)
- [CISA Alert — Phishing Guidance: Stopping the Attack Cycle at Phase One](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-215a)
- [BleepingComputer — Microsoft Warns of OAuth Redirect Attacks on Government Orgs](https://www.bleepingcomputer.com/news/security/microsoft-warns-of-oauth-redirect-attacks-on-government-orgs/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0173
