Security researchers reveal campaign promoting malicious Microsoft OAuth apps
The threat actors use the malicious apps to impersonate Adobe and DocuSign. The apps requests access to info such as name, user ID, profile picture, and email. Once the apps are authorized, the victim is redirected to a phishing form.
Administrators are advised to review authorized applications, and to limit users' ability to consent to third-party apps