Story perspectives
Microsoft Warns: Phishing Scams Exploit OAuth to Spread Malware
3/4/2026
1 of 1
Story summary
- Microsoft warns that phishing campaigns exploit OAuth URL redirection to deliver malware, targeting government and public-sector entities.
- Criminals craft benign-looking URLs that redirect users to malicious sites, enabling malware downloads.
- Phishing emails often contain links or malicious ZIP files that execute harmful commands when opened.
- Microsoft removed several malicious OAuth applications linked to these scams.
- To mitigate risk, organizations should limit user consent, review application permissions, and eliminate unused apps.
