Microsoft: OAuth apps used to automate BEC and crypto mining attacks
Microsoft alerts users to the use of OAuth applications by financially motivated threat actors to push spam, automate BEC and phishing attacks, and launch virtual machines (VMs) for cryptocurrency mining.
Open Authorization, or OAuth for short, is an open standard that uses token-based authentication and authorization in lieu of credentials to provide apps with secure delegated access to server resources based on user-defined permissions.
Attackers primarily target user accounts without strong authentication (such as multi-factor authentication) in phishing or password-spraying attacks, concentrating on those with the ability to create or modify OAuth apps read more OAuth apps used to automate BEC and crypto mining attacks.
Get up to date on the latest cybersecurity news and enha...

