owaauth
Malware⚠️ Overview
OwaAuth is a credential-harvesting malware family first documented by Microsoft Threat Intelligence in early 2022, operated by the threat actor tracked as DEV-0345 (later Storm-0345), and classified as a phishing toolkit and OAuth abuse framework targeting Microsoft 365 and Outlook Web App (OWA) environments. It leverages malicious OAuth applications to bypass multi-factor authentication (MFA) by tricking victims into granting permissions to a rogue application, thereby enabling persistent unauthorized access to email and cloud resources.
🔧 Technical Capabilities
OwaAuth propagates through spear‑phishing emails that contain a link to a legitimate OAuth consent page, but the attacker registers a malicious app (e.g., "OwaAuth") designed to request highly permissive scopes like `Mail.Read`, `Mail.Send`, and `User.Read` (MITRE ATT&CK T1525 – Abuse of OAuth Application). The attack vector relies on social engineering; no exploit or binary is executed on the victim’s device. Once the user approves the consent, the attacker obtains a refresh token that can be used from their own infrastructure (typically cloud‑hosted C2 servers) to exfiltrate emails, send phishing replies, or perform lateral movement via mailbox access. Persistence is achieved through the OAuth refresh token life cycle, which can be renewed without user interaction unless explicitly revoked. Evasion techniques include using legitimate Microsoft domains for the consent flow and encoding the malicious app ID in the URL to avoid file‑based detection.
📜 History & Notable Incidents
Microsoft’s 2022 report detailed DEV‑0345’s use of OwaAuth against at least 10,000 organizations, primarily in the non‑profit, education, and government sectors. A high‑profile campaign in March 2022 exploited the technique to compromise accounts affiliated with the Ukrainian government, as reported by Mandiant. No specific CVEs are associated with OwaAuth because it does not exploit software vulnerabilities; instead it abuses the OAuth permission model, which has been partially mitigated by Microsoft’s subsequent deprecation of “Basic Authentication” and the introduction of Conditional Access policies.
🔍 Detection Indicators
Network indicators include HTTP requests to `login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=
☠️ Risk & Impact
OwaAuth enables persistent data exfiltration of emails and attachments, leading to intellectual property theft, internal email‑driven phishing (reply‑to inbox attacks), and credential reuse across linked cloud services. Financial losses have been reported by organizations facing business email compromise (BEC) incidents that leveraged stolen emails to initiate fraudulent wire transfers, with the FBI’s 2022 IC3 report noting over $2.7 billion in BEC losses annually, of which OwaAuth‑style attacks contributed a significant share. The affected sectors widely include government, education, and non‑profits.
🛡️ Mitigation
[Recommended defensive measures, patches, detection rules, security tools – 1–2 sentences] Organizations should enforce Conditional Access policies blocking all third‑party OAuth apps unless explicitly approved, enable auditing of OAuth consent grants using Microsoft Defender for Cloud Apps (formerly Microsoft Cloud App Security), and deploy detection rules that alert on consent to applications with high‑risk permissions and mismatched publisher domains (e.g., rule ID 5cfd6a4a‑3b5c‑4b2e‑a0c8‑b9f8e2a1c3d7 from the Microsoft 365 Roadmap).
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.