ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Defending against OAuth abuse

Cloud services now sit at the centre of most organisations’ operations. Email, file sharing, messaging and identity management are all accessible from anywhere with an internet connection. That convenience has shifted the economics of cybercrime. Attackers no longer need to break through hardened network perimeters when they can target identities directly.

 

Once inside a cloud account, the objective has changed too. Attackers are investing in persistence, maintaining access quietly, surviving remediation efforts and turning short-lived compromises into long-term footholds.

 

OAuth abuse has become one of the most effective ways to do it.

 

From credential theft to OAuth persistence

Traditional account takeover methods such as password spraying and brute-force attacks still exist, but phishing frameworks built to capture authenticated sessions have raised the ceiling considerably. Toolkits including Tycoon and Evilginx proxy legitimate login flows through convincing fake pages, capturing session cookies after MFA is completed.

 

That distinction matters. The attacker does not need the password once they hold the authenticated session. In many environments, the cookie remains valid long enough to establish persistent access before security teams detect suspicious activity.

 

The next stage of the attack chain is where OAuth enters the picture.

 

In Microsoft Entra and similar cloud identity platforms, users can register applications inside their organisation’s tenant. In many environments, internally registered applications (2nd party apps) receive far less scrutiny than third-party applications, particularly where governance controls are inconsistent or immature. An attacker who compromises an account, even briefly, can register a malicious OAuth application, approve access scopes (like mail read), generate a secret and attach it to the 2nd party app and establish independent access to cloud resources.

 

At that point, the compromise stops being tied to the user login credentials.

 

Password resets alone often fail to remove the attacker’s access. The OAuth application continues operating with the permissions it was granted, allowing attackers to retain access to email, SharePoint data, Teams conversations and other cloud services after standard remediation steps are complete.

 

Proofpoint researchers observed exactly this behaviour during a real-world investigation. After compromising a user through the Tycoon phishing kit, the threat actor registered an internal application with Mail.Read permissions and maintained access for four days after the victim’s password had been changed. Activity was routed through US-based VPN infrastructure, blending into expected traffic patterns while the malicious application continued collecting data in the background.

 

The persistence mechanism itself requires relatively little sophistication. The challenge for defenders lies in visibility.

 

Malicious OAuth applications rarely stand out in administrative consoles. Attackers routinely use naming conventions, permission requests and registration patterns that resemble legitimate business software. In large enterprise tenants containing hundreds of internal applications, suspicious applications can disappear into the noise.

 

Proofpoint research also indicates that many organisations remain unfamiliar with OAuth weaponisation techniques and are not actively monitoring for signs of malicious application registration or secrets abuse.

 

MFA isn’t the safety net people think it is

Many organisations still view MFA as the definitive control against account compromise. In practice, attackers have spent years adapting around it.

 

Modern phishing kits capture authenticated sessions after MFA validation occurs. The attacker inherits the trusted session without needing the password or one-time code. From the victim’s perspective, the login flow often appears normal.

 

FIDO-based authentication remains significantly stronger because it relies on device-bound cryptographic authentication rather than reusable credentials. Even so, downgrade paths remain a concern.

 

Proofpoint researchers have observed attackers manipulating authentication flows to push users towards weaker MFA methods such as SMS verification. Some threat groups are also discussing future approaches targeting FIDO-protected workflows, although widespread operational use has yet to emerge.

 

That matters because many organisations still structure their response playbooks around assumptions that no longer fully reflect attacker behaviour. Credential resets and MFA enforcement remain important controls, but they are increasingly insufficient on their own.

 

AI is scaling the problem

The operational burden of maintaining persistent cloud access used to limit how many compromised identities attackers could realistically manage. Tokens and secrets expire and require rotations.

 

Automation is removing much of that friction.

 

Attackers are increasingly automating token management, session monitoring and persistence workflows across large numbers of compromised accounts. Tasks that once demanded hands-on coordination can now run continuously with minimal oversight.

 

A small team can manage hundreds of active compromises simultaneously, tracking token expiry windows, refreshing access and maintaining long-term persistence across multiple tenants.

 

That shift industrialises cloud compromise. More accounts remain active for longer periods. Dwell times increase. Detection teams face larger volumes of low-noise activity spread across legitimate cloud infrastructure.

 

Security teams built many of their response processes around an earlier generation of attacks: reset credentials, revoke sessions, enforce MFA and close the incident.

 

Today’s cloud-focused attackers operate differently. Defenders need visibility into OAuth application activity, token persistence and post-authentication behaviour, not just compromised credentials.

 


 

Yaniv Miron is Director of Threat Research at Proofpoint, leading the cloud and AI threat research teams

 

Main image courtesy of iStockPhoto.com and mustafaU


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543