Microsoft Investigation - Threat actor consent phishing campaign abusing the verified publisher process

  • Thread starter Thread starter MSRC
  • Start date Start date
M

MSRC

Summary On December 15th, 2022, Microsoft became aware of a consent phishing campaign involving threat actors fraudulently impersonating legitimate companies when enrolling in the Microsoft Cloud Partner Program (MCPP) (formerly known as Microsoft Partner Network (MPN)). The actor used fraudulent partner accounts to add a verified publisher to OAuth app registrations they created in Azure AD.

Continue reading...
 
Back
Top