{"id":7885,"date":"2025-10-23T10:03:32","date_gmt":"2025-10-23T10:03:32","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/23\/hackers-weaponizing-oauth-applications-for-persistent-cloud-access-even-after-password-reset\/"},"modified":"2025-10-23T10:03:32","modified_gmt":"2025-10-23T10:03:32","slug":"hackers-weaponizing-oauth-applications-for-persistent-cloud-access-even-after-password-reset","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/23\/hackers-weaponizing-oauth-applications-for-persistent-cloud-access-even-after-password-reset\/","title":{"rendered":"Hackers Weaponizing OAuth Applications for Persistent Cloud Access Even After Password Reset"},"content":{"rendered":"<p>    Hackers Weaponizing OAuth Applications for Persistent Cloud Access Even After Password Reset<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cloud account takeover attacks have evolved into a sophisticated threat as cybercriminals and state-sponsored actors increasingly weaponize OAuth applications to establish persistent access within compromised environments.<\/p>\n<p>These malicious actors are exploiting the fundamental trust mechanisms of cloud authentication systems, specifically targeting Microsoft Entra ID environments where they can hijack user accounts, conduct reconnaissance, exfiltrate sensitive data, and launch subsequent attacks with alarming effectiveness.<\/p>\n<p>The security implications of this attack vector are particularly severe because attackers can create and authorize internal second-party applications with custom-defined scopes and permissions once they gain initial access to a cloud account.<\/p>\n<p>This capability enables persistent access to critical organizational resources including mailboxes, SharePoint documents, OneDrive files, Teams messages, and calendar information.<\/p>\n<p>Traditional security measures like password resets and <a href=\"https:\/\/cybersecuritynews.com\/multifactor-authentication-is-mandatory-for-azure\/\" target=\"_blank\" rel=\"noreferrer noopener\">multifactor authentication<\/a> enforcement prove ineffective against these attacks, as the malicious OAuth applications maintain their authorized access independently of user credential changes.<\/p>\n<p>Proofpoint analysts <a href=\"https:\/\/www.proofpoint.com\/us\/blog\/threat-insight\/beyond-credentials-weaponizing-oauth-applications-persistent-cloud-access\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this emerging threat pattern through extensive research and real-world incident analysis, developing an automated toolkit that demonstrates how threat actors establish resilient backdoors within cloud environments.<\/p>\n<p>Their investigation revealed that attackers typically gain initial access through reverse proxy toolkits accompanied by individualized phishing lures that enable the theft of both credentials and session cookies.<\/p>\n<p>Once inside, attackers leverage the compromised account\u2019s privileges to register new internal applications that appear as legitimate business resources within the organization\u2019s tenant.<\/p>\n<p>The persistence mechanism operates through a carefully orchestrated process where attackers create second-party applications that inherit implicit trust within the environment.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiYBFYHBCW5wkH1qQLNnXKJGQGSigYgULBdufbLz1qZNhghKuGjf79uoYrUQtMvoyioEWe80L8XFAFpceOXmbP4TTemwAbB78jkD3B2RllVUf6U5eWNzvY5mvKNdUVQ7N73KtST58cjOAMXZ9ZlJ4ZSfB8ValvYpTI7tYvcEEe_RZqwft-SGGSTlQz4_X8\/s16000\/Application%2520creation%2520process%2520%28Source%2520-%2520Proofpoint%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Application creation process (Source \u2013 Proofpoint)<\/figcaption><\/figure>\n<\/div>\n<p>These internal applications are more difficult to detect than third-party applications because they bypass security controls designed primarily for external application monitoring.<\/p>\n<p>The malicious applications can remain undetected within the environment indefinitely unless specifically identified through proactive security auditing, creating a substantial window of opportunity for <a href=\"https:\/\/cybersecuritynews.com\/cl0p-ransomware-data-exfiltration-vulnerable\/\" target=\"_blank\" rel=\"noreferrer noopener\">data exfiltration<\/a> and reconnaissance activities.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-automated-oauth-persistence-technical-implementation\"><strong>Automated OAuth Persistence: Technical Implementation<\/strong><\/h2>\n<p>The technical sophistication of these attacks becomes evident through automated OAuth application registration and configuration processes.<\/p>\n<p>Attackers deploy tools that streamline post-exploitation activities, registering applications with pre-configured permission scopes aligned with their objectives.<\/p>\n<p>A critical aspect involves establishing the compromised user account as the registered owner of the newly created application, effectively positioning it as a legitimate internal resource that inherits trust relationships associated with internal systems.<\/p>\n<p>During the automated deployment, attackers generate cryptographic client secrets that serve as the application\u2019s authentication credentials, typically configured with extended validity periods of up to two years.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiH-aGzaNyUIuTPFgougqVPhsydS2Ye1HcPuvEHF-CHY3nBf-xY4bVgWsS5zgmXBLPAIKsT_zXjJ4XpMDRA03XpVILQl0yBSeqgSSZnJ0fBcMuuIBcEqUGUfSkOJOfZyA4d1LFj-k2RyYjqhPEh9pqBXCS1GALJryy_P9An08ybjoZMyxtGb8AQ_dp1bdQ\/s16000\/Tokens%2520collected%2520%28Source%2520-%2520Proofpoint%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Tokens collected (Source \u2013 Proofpoint)<\/figcaption><\/figure>\n<\/div>\n<p>The automation then collects multiple <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploit-microsoft-365-oauth-workflows\/\" target=\"_blank\" rel=\"noreferrer noopener\">OAuth<\/a> token types including access tokens, refresh tokens, and ID tokens, each serving distinct purposes in maintaining persistent access.<\/p>\n<p>Proofpoint researchers documented a real-world incident where attackers operating through US-based VPN proxies created an internal application named \u2018test\u2019 with Mail.Read and offline_access permissions, maintaining access for four days even after the victim\u2019s password was changed.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-weaponizing-oauth-applications\/\">Hackers Weaponizing OAuth Applications for Persistent Cloud Access Even After Password Reset<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-weaponizing-oauth-applications\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Weaponizing OAuth Applications for Persistent Cloud Access Even After Password Reset Cloud account takeover attacks have evolved into a sophisticated threat as cybercriminals and state-sponsored actors increasingly weaponize OAuth applications to establish persistent access within compromised environments. These malicious actors are exploiting the fundamental trust mechanisms of cloud authentication systems, specifically targeting Microsoft Entra [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7885","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7885"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7885"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7885\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7885"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7885"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}