Wednesday, August 19, 2026
  • Subscribe
  • Advertise
  • Advertising Specifications
  • Editorial
  • Editorial Features
  • About Us
  • Contact
Networking+
  • Latest News
  • Magazine Topics
  • Technologies
  • Magazine Issues
No Result
View All Result
  • Latest News
  • Magazine Topics
  • Technologies
  • Magazine Issues
No Result
View All Result
Networking+
No Result
View All Result
Home Technologies Management, Monitoring & Optimisation

Phishing campaign employing counterfeit Microsoft OAuth applications to bypass MFA revealed

August 22, 2025
Reading Time: 2 mins read
Share on LinkedInShare on Twitter


Proofpoint has uncovered a sophisticated phishing campaign employing counterfeit Microsoft OAuth applications to bypass Multi-Factor Authentication (MFA) and illicitly access Microsoft 365 accounts.

The threat actors behind this operation are creating fake OAuth apps that impersonate well-known brands like Adobe, DocuSign, and SharePoint. These malicious applications are used in Attacker-in-the-Middle (AiTM) phishing attacks, primarily leveraging the Tycoon phishing kit to steal user credentials and intercept MFA tokens.

In their research, Proofpoint identified over 50 different impersonated applications and nearly 3,000 attempted breaches across more than 900 environments. The success rate of these attacks has exceeded 50% in 2025. The campaigns are often tailored to specific industries; for example, some targeting aerospace and defence sectors use language such as “request-for-quotes” (RFQs) and impersonate industry-specific services like ILSMart, indicating highly customised attack approaches.

The attack sequence typically starts with phishing emails sent from compromised accounts, containing links to fake OAuth consent pages. Users are prompted to grant permissions to what seems to be legitimate applications. Whether users accept or decline these permissions, they are then redirected to a counterfeit Microsoft login page that mimics the organisation’s Entra ID branding. This fake login page captures credentials and intercepts MFA tokens in real-time using AiTM techniques, granting attackers full access to the compromised accounts.

Much of this malicious activity is linked to the Tycoon Phishing-as-a-Service platform, which is designed to intercept credentials and session cookies in real time, effectively bypassing MFA protections. Notably, Proofpoint observed a shift in the operational infrastructure of these threat actors, moving from Russian proxy servers to US-based data centres, likely as an effort to evade detection.

To defend against these evolving threats, experts recommend a combination of strategies. Organisations should monitor and block malicious emails, detect account takeover attempts, and employ rapid detection and auto-remediation solutions to minimise attackers’ dwell time. Implementing web session isolation and ongoing user education about suspicious Microsoft 365 requests are also crucial. Additionally, organisations are advised to consider adopting FIDO-based physical security keys to strengthen authentication.

Proofpoint also anticipates that upcoming Microsoft 365 updates, scheduled between July and August 2025, will significantly disrupt these attack methods. The updates will eliminate legacy authentication protocols and require administrative approval for third-party app access, making it more difficult for threat actors to exploit these vulnerabilities.

 

Related Posts

Top 5 Digital Twin Software for Telecom Towers in 2026
Cloud & Virtualisation

Top 5 Digital Twin Software for Telecom Towers in 2026

August 17, 2026
Partners group to become majority shareholder in data centre power solutions provider AVK and accelerate future growth
Cloud & Virtualisation

Vodafone Business and Tata Consultancy Services partner to unlock UK enterprise transformation

August 13, 2026
Partners group to become majority shareholder in data centre power solutions provider AVK and accelerate future growth
Data Centres

Partners group to become majority shareholder in data centre power solutions provider AVK and accelerate future growth

August 13, 2026
Network automation and autonomy phase III: agentic AI for autonomous mobile networks
Critical Communications

Network automation and autonomy phase III: agentic AI for autonomous mobile networks

August 13, 2026

Subscribe

Get the latest networking news and insights delivered to your inbox.

SIGN UP

READ THE LATEST ISSUE

Networking+ is the premier independent resource for communications, network, IT, and data centre professionals. We provide an in-depth look at the rapidly evolving digital infrastructure landscape, covering everything from fixed and wireless LANs to complex enterprise WANs and MANs across both the public and private sectors.

By delivering breaking news, expert analysis, and strategic insights across our print publication, website, and e-newsletters, Networking+ offers a powerful, ‘one-stop’ media combination. Our multi-channel platform is dedicated to keeping industry decision-makers connected, informed, and equipped to future-proof their networks.

Follow Us

Content

  • Magazine
  • Technologies
  • Subscribe
  • Editorial
  • Advertise
  • About Us
  • Features List
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions

© 2026 Networking+ - A Denyan Media Ltd Publication.

No Result
View All Result
  • Latest News
  • Magazine Topics
  • Technologies
  • Magazine Issues
  • Advertise
  • Advertising Specifications
  • Editorial
  • Editorial Features
  • About Us

© 2026 Networking+ - A Denyan Media Ltd Publication.

We use cookies to analyse site traffic and improve your experience with the latest enterprise networking insights. By clicking 'OK', you consent to our use of cookies in accordance with our Privacy Policy.