• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Thursday, September 11, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Attackers abuse OAuth apps to initiate large-scale cryptomining and spam campaigns

13 December 2023
in Mining
Reading Time: 3 mins read
A A
0
Attackers abuse OAuth apps to initiate large-scale cryptomining and spam campaigns
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024

Attackers are compromising high-privilege Microsoft accounts and abusing OAuth applications to launch a variety of financially-motivated attacks.

Abusing OAuth applications

OAuth is an open standard authentication protocol that uses tokens to grant applications access to server resources without having to use login credentials.

Microsoft Threat Intelligence has observed a number of attacks that started with attackers compromising (either via phishing or password spraying) poorly secured accounts that have permissions to create, modify, and grant high privileges to OAuth applications.

They can then misuse these applications to hide malicious activity and maintain access to the apps even if they lose access to the initially compromised account, the analysts noted.

Cryptomining, phishing and spam

In one of the detected attacks, the attackers generated an OAuth application to deploy virtual machines (VMs) used for cryptocurrency mining.

The compromised account allowed them to:

  • Sign in via VPN
  • Create a new single-tenant OAuth application in Microsoft Entra ID and add a set of secrets to the app
  • Grant “Contributor” role permission for the application to one of the active subscriptions using the compromised account
  • Use existing line-of-business OAuth applications (by adding an additional set of credentials to those applications)

OAuth application for cryptocurrency mining attack chain. (Source: Microsoft Threat Intelligence)

“The actor initially deployed a small set of VMs in the same compromised subscriptions using one of the existing applications and initiated the cryptomining activity. The actor then later returned to deploy more VMs using the new application,” the analysts shared.

“Targeted organizations incurred compute fees ranging from 10,000 to 1.5 million USD from the attacks, depending on the actor’s activity and duration of the attack.”

In another attack, after having created OAuth applications, the attackers started sending out phishing emails by leveraging an adversary-in-the-middle (AiTM) phishing kit. This allowed them to steal the user’s session cookie token and perform session cookie replay activity.

In some instances, the attackers used the compromised accounts to find emails mentioning payments or invoices, so they can insert themselves in the email conversation and redirect payments to their own banking accounts.

Other instances saw the attackers creating multitenant OAuth applications to gain persistence, adding new credentials, creating inbox rules to move emails to the junk folder and mark them as read, and reading emails or sending phishing emails via Microsoft Graph API.

abusing OAuth applications

Attack chain for OAuth application misuse for phishing. (Source: Microsoft Threat Intelligence)

“At the time of analysis, we observed that threat actor created around 17,000 multitenant OAuth applications across different tenants using multiple compromised user accounts,” the researchers noted, and added that the malicious OAuth applications created by the threat actor sent more than 927,000 phishing emails.

OAuth apps are often (ab)used

While in these attacks OAuth apps are leveraged to gain persistence to compromised accounts and to extend the attacks, attackers have also been known to use seemingly verified (but malicious) third-party OAuth apps to gain access to O365 email accounts.

Microsoft’s threat analysts have shared detections and hunting guidance to help defenders and threat hunters check for suspicious activity related to these latest attacks.

They also listed mitigation steps organizations can take to protect themselves, which include: protecting accounts with multi-factor authentication, enabling conditional access policies, enabling Microsoft Defender automatic attack disruption, auditing apps and permissions, and more.

Source link

Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: AbuseAppsAttackerscampaignsCryptoMiningInitiatelargescaleOAuthSpam
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Analyst Warns Against Extreme Expectations Ahead Of Bitcoin Spot ETF Approvals

Next Post

BlackRock Has Quietly Opened The Door To A ‘Trillion-Dollar Plus’ Wall Street Game-Changer Amid The $700 Billion Bitcoin, Ethereum, XRP And Crypto Price Boom

Related Posts

No, Russia did not just lift its ban on domestic crypto use

No, Russia did not just lift its ban on domestic crypto use

30 July 2024
0

A fake news story circulated today about Russia’s supposed embrace of bitcoin mining and crypto payments. According to excited social...

New US Bitcoin Mining Hardware Creates B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

New US Bitcoin Mining Hardware Creates $20B Opportunity, Could Disrupt China’s Mining Dominance: Bernstein – Canaan (NASDAQ:CAN)

30 July 2024
0

A new report estimates a $20 billion revenue opportunity in Bitcoin BTC/USD mining chips and hardware over the next five...

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

Russia Races to Legalize Crypto as Sanctions Weigh On Firms – BNN Bloomberg

30 July 2024
0

(Bloomberg) -- Russia is moving to regulate the use of cryptocurrencies, as companies wrestle with increasing difficulties in foreign payments...

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

Russia Advances Crypto and Mining Regulations as US Sanctions Impact Economy

30 July 2024
0

The Russian central bank plans to initiate international payments in cryptocurrencies by the end of the year to overcome delays...

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

Wall Street Bitcoin Miner Taps Institutional Investor for £6.5 Million Capital Boost

30 July 2024
0

Listed both on Wall Street and the London Stock Exchange (LSE) Bitcoin miner Argo Blockchain, has announced a £6.5 million...

Load More
Next Post
BlackRock Has Quietly Opened The Door To A ‘Trillion-Dollar Plus’ Wall Street Game-Changer Amid The 0 Billion Bitcoin, Ethereum, XRP And Crypto Price Boom

BlackRock Has Quietly Opened The Door To A ‘Trillion-Dollar Plus’ Wall Street Game-Changer Amid The $700 Billion Bitcoin, Ethereum, XRP And Crypto Price Boom

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Ethereum Investors Double Down As Staking Activity Spikes Sharply – Here’s How Much

Ethereum Investors Double Down As Staking Activity Spikes Sharply – Here’s How Much

11 September 2025
Big Solana News: Latest Developments Could Ignite Major Price Surge – TechFinancials

Big Solana News: Latest Developments Could Ignite Major Price Surge – TechFinancials

11 September 2025
Why New Crypto Investors Favour Backing Layer Brett Over Solana In September

Why New Crypto Investors Favour Backing Layer Brett Over Solana In September

11 September 2025
ADA Price Holds Key Support Despite 0M Whale Sell-Off

ADA Price Holds Key Support Despite $140M Whale Sell-Off

11 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Ethereum Investors Double Down As Staking Activity Spikes Sharply – Here’s How Much
  • Big Solana News: Latest Developments Could Ignite Major Price Surge – TechFinancials
  • Why New Crypto Investors Favour Backing Layer Brett Over Solana In September
  • ADA Price Holds Key Support Despite $140M Whale Sell-Off
  • Here’s why Bitwise is tipping Solana for an end-of-year rally. And what could stall it – Yahoo Finance

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 114,501.00
  • ethereumEthereum (ETH) $ 4,415.38
  • xrpXRP (XRP) $ 2.99
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 894.70
  • solanaSolana (SOL) $ 226.03
  • usd-coinUSDC (USDC) $ 0.999781
  • staked-etherLido Staked Ether (STETH) $ 4,408.37
  • dogecoinDogecoin (DOGE) $ 0.249369
  • tronTRON (TRX) $ 0.345382
  • cardanoCardano (ADA) $ 0.878300
  • wrapped-stethWrapped stETH (WSTETH) $ 5,350.23
  • chainlinkChainlink (LINK) $ 23.59
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,759.57
  • hyperliquidHyperliquid (HYPE) $ 54.72
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 114,507.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.60
  • stellarStellar (XLM) $ 0.387236
  • figure-helocFigure Heloc (FIGR_HELOC) $ 0.993492
  • avalanche-2Avalanche (AVAX) $ 28.93
  • wrapped-eethWrapped eETH (WEETH) $ 4,747.74
  • bitcoin-cashBitcoin Cash (BCH) $ 588.95
  • wethWETH (WETH) $ 4,417.07
  • hedera-hashgraphHedera (HBAR) $ 0.234328
  • leo-tokenLEO Token (LEO) $ 9.57
  • litecoinLitecoin (LTC) $ 114.21
  • crypto-com-chainCronos (CRO) $ 0.258108
  • the-open-networkToncoin (TON) $ 3.19
  • usdsUSDS (USDS) $ 0.999783
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 114,516.00
  • polkadotPolkadot (DOT) $ 4.18
  • whitebitWhiteBIT Coin (WBT) $ 43.46
  • uniswapUniswap (UNI) $ 9.77
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.199995
  • ethenaEthena (ENA) $ 0.765466
  • mantleMantle (MNT) $ 1.59
  • moneroMonero (XMR) $ 269.13
  • aaveAave (AAVE) $ 302.84
  • bitget-tokenBitget Token (BGB) $ 4.88
  • daiDai (DAI) $ 0.999381
  • pepePepe (PEPE) $ 0.000010
  • okbOKB (OKB) $ 195.20
  • bittensorBittensor (TAO) $ 353.13
  • nearNEAR Protocol (NEAR) $ 2.70
  • jito-staked-solJito Staked SOL (JITOSOL) $ 278.13
  • ethereum-classicEthereum Classic (ETC) $ 21.19