Proofpoint has uncovered a sophisticated phishing campaign employing counterfeit Microsoft OAuth applications to bypass Multi-Factor Authentication (MFA) and illicitly access Microsoft 365 accounts.
The threat actors behind this operation are creating fake OAuth apps that impersonate well-known brands like Adobe, DocuSign, and SharePoint. These malicious applications are used in Attacker-in-the-Middle (AiTM) phishing attacks, primarily leveraging the Tycoon phishing kit to steal user credentials and intercept MFA tokens.
In their research, Proofpoint identified over 50 different impersonated applications and nearly 3,000 attempted breaches across more than 900 environments. The success rate of these attacks has exceeded 50% in 2025. The campaigns are often tailored to specific industries; for example, some targeting aerospace and defence sectors use language such as “request-for-quotes” (RFQs) and impersonate industry-specific services like ILSMart, indicating highly customised attack approaches.
The attack sequence typically starts with phishing emails sent from compromised accounts, containing links to fake OAuth consent pages. Users are prompted to grant permissions to what seems to be legitimate applications. Whether users accept or decline these permissions, they are then redirected to a counterfeit Microsoft login page that mimics the organisation’s Entra ID branding. This fake login page captures credentials and intercepts MFA tokens in real-time using AiTM techniques, granting attackers full access to the compromised accounts.
Much of this malicious activity is linked to the Tycoon Phishing-as-a-Service platform, which is designed to intercept credentials and session cookies in real time, effectively bypassing MFA protections. Notably, Proofpoint observed a shift in the operational infrastructure of these threat actors, moving from Russian proxy servers to US-based data centres, likely as an effort to evade detection.
To defend against these evolving threats, experts recommend a combination of strategies. Organisations should monitor and block malicious emails, detect account takeover attempts, and employ rapid detection and auto-remediation solutions to minimise attackers’ dwell time. Implementing web session isolation and ongoing user education about suspicious Microsoft 365 requests are also crucial. Additionally, organisations are advised to consider adopting FIDO-based physical security keys to strengthen authentication.
Proofpoint also anticipates that upcoming Microsoft 365 updates, scheduled between July and August 2025, will significantly disrupt these attack methods. The updates will eliminate legacy authentication protocols and require administrative approval for third-party app access, making it more difficult for threat actors to exploit these vulnerabilities.










