< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Cybercriminals target enterprise accounts via OAuth and BitB phishing

Cybersecurity researchers and the FBI have issued warnings regarding sophisticated phishing campaigns that utilize OAuth consent and Browser-in-the-Browser (BitB) techniques to hijack enterprise accounts.

Researchers at Zimperium have identified a recruitment-themed campaign where attackers impersonate HR employees from major corporations, including Amazon, Apple, Boeing, and Deloitte. These attackers use BitB attacks to create realistic, simulated browser windows that trick job seekers into providing credentials. The phishing kit specifically targets high-value enterprise users by screening out personal email domains, aiming to gain access to OAuth tokens and internal corporate communications.

Mobile users are noted as being particularly vulnerable because the BitB frame often adapts into a full-screen counterfeit login page, removing the visual indicators like URL bars that typically signal a fake site.

Complementing these findings, the FBI warned that OAuth consent phishing allows attackers to bypass traditional password theft. Instead of stealing credentials, attackers trick users into authorizing malicious applications. Once a user clicks ‘Allow’ or ‘Accept’ on a deceptive authorization prompt, the attacker gains permission to read emails, access files, and maintain persistent access to the account without ever needing the user's password.

Entities

Amazon · Apple · Boeing · FBI · Zimperium