< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [CRIME]

2 clusters · 6 sources · 2 days · First seen · Last updated

OAuth and BitB phishing campaigns

Overview

Cybersecurity researchers and the FBI have identified sophisticated phishing campaigns targeting enterprise accounts and individuals through OAuth consent and Browser-in-the-Browser (BitB) techniques.

Initial reports highlighted recruitment-themed campaigns where attackers impersonate HR employees from major corporations like Amazon, Apple, and Boeing. These attackers utilize BitB attacks to create simulated browser windows that trick users into providing credentials. Mobile users are especially at risk as the BitB frame can adapt into a full-screen counterfeit login page that hides URL indicators.

Subsequent warnings from the FBI clarified that OAuth consent phishing allows criminals to bypass traditional password theft. Instead of stealing passwords, attackers trick users into authorizing malicious applications. By clicking ‘Allow’ or ‘Accept’ on a deceptive prompt, users grant attackers permission to read emails and access files, providing persistent access to the account without the need for a password. In these instances, attackers may impersonate government officials or media representatives to initiate contact via messaging apps.

Entities

FBI · Google · Microsoft · Boeing · Amazon

Timeline

  1. 7 days ago

    [CRIME] 3 sources
    FBI warns of OAuth consent phishing attacks

    The FBI warns of OAuth consent phishing where attackers bypass passwords by tricking users into granting app permissions. Meanwhile, Polish police have arrested eight suspects for BLIK-related fraud.

  2. 9 days ago

    [TECHNOLOGY] 3 sources
    Cybercriminals target enterprise accounts via OAuth and BitB phishing

    Cybercriminals are using OAuth consent and Browser-in-the-Browser attacks to hijack enterprise accounts by impersonating HR staff and tricking users into authorizing malicious applications.

Sources

asaaseradio.com · blog.knowbe4.com · crn.pl · cyberdefence24.pl · informacija.rs · telepolis.pl