Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesCopyBotsEarn
Microsoft researchers: OAuth app used to automate phishing attacks and mine cryptocurrency

Microsoft researchers: OAuth app used to automate phishing attacks and mine cryptocurrency

CointimeCointime2023/12/16 07:56
By:Cointime

Microsoft researchers have discovered a series of cyber attacks where OAuth applications are used to automatically conduct phishing attacks, disrupt company emails, and secretly mine cryptocurrency. The hackers' targets are accounts that lack strong authentication mechanisms. They create new OAuth applications with high permissions through hijacked accounts, allowing malware to access systems without the user's knowledge.

In one case, an attacker with the username Storm-1283 used OAuth to deploy virtual machines for cryptocurrency mining. Depending on the duration of the attack, losses ranged from $10,000 to $1.5 million.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Locked for new tokens.
APR up to 10%. Always on, always get airdrop.
Lock now!

You may also like

Live hearing coverage – Investigating the real impacts of debanking in America

Share link:In this post: The Senate Banking Committee held a hearing on allegations that banks unfairly denied services to crypto firms and individuals based on political affiliations – The American debanking. Anchorage Digital CEO and legal experts testified on widespread debanking, with concerns over regulatory overreach and a potential “Operation Chokepoint 3.0.” Sen. Tim Scott and Sen. Elizabeth Warren criticized debanking, with Scott calling it “un-American” and Warren citing nearly 12,000 related com

Cryptopolitan2025/02/05 19:55

MicroStrategy rebrands to Strategy reflecting its Bitcoin focus

Share link:

Cryptopolitan2025/02/05 19:55

Musk wants suit over Tesla’s use of AI-generated ‘Blade Runner’ imagery dropped

Share link:In this post: Musk’s attorneys have said that both Musk and Tesla will move to dismiss “all claims” for relief with prejudice. The plaintiff in the suit, Alcon Entertainment, intends to oppose the motion. Tesla is set to launch unsupervised Full Self-Driving as a paid service in Austin in June.

Cryptopolitan2025/02/05 19:55