• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Sunday, September 21, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Microsoft Warns of OAuth Attacks Tied to Cryptomining

13 December 2023
in Mining
Reading Time: 3 mins read
A A
0
Microsoft Warns of OAuth Attacks Tied to Cryptomining
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT
Cryptohopper
ADVERTISEMENT

Microsoft Details OAuth Tactics, Says Losses Reached Up to $1.5M Per Victim

Prajeet Nair (@prajeetspeaks) •
December 13, 2023    


Hackers are exploiting OAuth applications to compromise user accounts, manipulate and confer elevated privileges, and set up cryptomining operations, which has cost some organizations up to $1.5 million in losses, according to Microsoft’s Threat Intelligence team.

See Also: Entering the Era of Generative AI-Enabled Security

This abuse of OAuth enhances the ability of adversaries to maintain access to applications, persisting even in situations in which the originally compromised account is no longer available.

Single sign-on standard OAuth or Open Authorization is a protocol for token-centric authentication and authorization that empowers applications to acquire access to data and resources based on permissions defined by the user (see: Warning: Careless OAuth Implementation Puts Billions at Risk).

The Microsoft Threat Intelligence team observed that the cyberthreat actors executed phishing and password-spraying attacks, targeting user accounts that lacked authentication safeguards and possessed the authority to create or modify OAuth applications.

“The threat actors misused the OAuth applications with high privilege permissions to deploy virtual machines for cryptocurrency mining, establish persistence following business email compromise, and launch spamming activity using the targeted organization’s resources and domain name,” the researchers said.

They spotted threat actor Storm-1283 exploiting a compromised user account to execute a cryptomining operation. It used the compromised account to sign in through a virtual private network, creating a new single-tenant OAuth application within Microsoft Entra ID.

The Redmond giant said that this application bore a striking resemblance to the Microsoft Entra ID tenant domain name, camouflaging its malicious intent. To enhance its functionality, a set of secrets was discreetly added to the application, the researchers said.

The compromised account’s ownership role on an Azure subscription also helped Storm-1283 gain further access. The threat actor, using the account’s privileges, granted “Contributor” role permissions to the application, empowering it to access and manipulate one of the active subscriptions.

Hackers then capitalized on pre-existing line-of-business OAuth applications accessible to the compromised user account within the tenant. They achieved this by introducing an additional set of credentials to augment the capabilities of these applications.

The actor deployed a limited number of virtual machines within the same compromised subscriptions, initiating the cryptomining operations using one of the existing applications. Subsequently, the actor revisited the scene and deployed additional VMs using the newly created application.

“Targeted organizations incurred compute fees ranging from 10,000 to 1.5 million USD from the attacks, depending on the actor’s activity and duration of the attack,” Microsoft said.

Storm-1283 aimed to prolong the configuration for an extended duration to enhance the likelihood of successful cryptomining operations. To mitigate suspicion, the actor strategically employed a specific naming convention for the virtual machines, utilizing [DOMAINNAME][ZONENAME][1-9], a format comprising the tenant name followed by the region name.

Microsoft said it recognized the behavior of this actor by monitoring VM creation in Azure Resource Manager audit logs and looking for the activity “Microsoft.Compute/virtualMachines/write” performed by an OAuth application. While the naming convention used by the actor may change in time, it may still include the domain name or region names such as “east|west|south|north|central|japan|france|australia|canada|korea|uk|poland|brazil,” the researchers said.

Microsoft said it had detected this activity and collaborated with the Microsoft Entra team to neutralize the OAuth applications implicated in this attack. The company also said that it had notified affected organizations about this malicious activity and provided recommendations for further actions to safeguard their digital infrastructure.

Microsoft also detailed how threat actors had compromised user accounts and misused OAuth applications for their financially driven attacks, and it outlined recommendations for organizations to mitigate such attacks.

The company also provided detailed information on how Microsoft detects related activity for OAuth applications for BEC and phishing and for spamming activity, mitigation steps, detections for related techniques, and threat hunting guidance.



Source link

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
[crypto-donation-box]
Tags: AttacksCryptoMiningMicrosoftOAuthtiedwarns
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

$100 Weekly Investment Since Peak is Worth This Much

Next Post

Social Giant Line Raises $140 Million for NFT Push, ‘Brown and Friends’ Games

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
Social Giant Line Raises 0 Million for NFT Push, ‘Brown and Friends’ Games

Social Giant Line Raises $140 Million for NFT Push, 'Brown and Friends' Games

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Managing Crypto Payroll for BNB: Navigating Risks and Strategies – OneSafe

Managing Crypto Payroll for BNB: Navigating Risks and Strategies – OneSafe

20 September 2025
Is A New Bullish Phase About To Commence?

Is A New Bullish Phase About To Commence?

20 September 2025
Investing in Crypto: 2025’s Leading Coins Compared; BlockDAG, NEAR, BNB & TRX – livebitcoinnews.com

Investing in Crypto: 2025’s Leading Coins Compared; BlockDAG, NEAR, BNB & TRX – livebitcoinnews.com

20 September 2025
Solana price prediction, Cardano news & which is the best crypto to buy now – Latest news from Azerbaijan

Solana price prediction, Cardano news & which is the best crypto to buy now – Latest news from Azerbaijan

20 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Managing Crypto Payroll for BNB: Navigating Risks and Strategies – OneSafe
  • Is A New Bullish Phase About To Commence?
  • Investing in Crypto: 2025’s Leading Coins Compared; BlockDAG, NEAR, BNB & TRX – livebitcoinnews.com
  • Solana price prediction, Cardano news & which is the best crypto to buy now – Latest news from Azerbaijan
  • BNB Surges Past $1000: Binance Coin’s New Era in the Crypto Race – Azat TV

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 115,730.00
  • ethereumEthereum (ETH) $ 4,479.43
  • xrpXRP (XRP) $ 2.99
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 1,073.75
  • solanaSolana (SOL) $ 241.03
  • usd-coinUSDC (USDC) $ 0.999662
  • dogecoinDogecoin (DOGE) $ 0.268348
  • staked-etherLido Staked Ether (STETH) $ 4,474.76
  • cardanoCardano (ADA) $ 0.896911
  • tronTRON (TRX) $ 0.345653
  • wrapped-stethWrapped stETH (WSTETH) $ 5,434.88
  • chainlinkChainlink (LINK) $ 23.37
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,831.47
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 115,650.00
  • hyperliquidHyperliquid (HYPE) $ 54.07
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • avalanche-2Avalanche (AVAX) $ 33.04
  • suiSui (SUI) $ 3.67
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.00
  • stellarStellar (XLM) $ 0.387640
  • bitcoin-cashBitcoin Cash (BCH) $ 598.90
  • wrapped-eethWrapped eETH (WEETH) $ 4,821.29
  • wethWETH (WETH) $ 4,482.73
  • hedera-hashgraphHedera (HBAR) $ 0.242149
  • leo-tokenLEO Token (LEO) $ 9.50
  • litecoinLitecoin (LTC) $ 114.39
  • usdsUSDS (USDS) $ 0.999987
  • crypto-com-chainCronos (CRO) $ 0.229334
  • the-open-networkToncoin (TON) $ 3.09
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 115,753.00
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • polkadotPolkadot (DOT) $ 4.36
  • whitebitWhiteBIT Coin (WBT) $ 43.36
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.227885
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • uniswapUniswap (UNI) $ 9.20
  • moneroMonero (XMR) $ 296.91
  • mantleMantle (MNT) $ 1.67
  • ethenaEthena (ENA) $ 0.674599
  • daiDai (DAI) $ 0.999620
  • aaveAave (AAVE) $ 298.00
  • pepePepe (PEPE) $ 0.000011
  • okbOKB (OKB) $ 203.47
  • memecoreMemeCore (M) $ 2.54
  • story-2Story (IP) $ 12.66
  • nearNEAR Protocol (NEAR) $ 3.13
  • bitget-tokenBitget Token (BGB) $ 5.37
  • jito-staked-solJito Staked SOL (JITOSOL) $ 297.14