ADVERTISEMENT

Microsoft warning: attackers are abusing Google logins to spread malware

Hackers are hijacking trusted OAuth login flows to redirect victims to phishing traps, where they unknowingly download malware.

Microsoft phishing

Image by Cybernews

Paulina Okunytė
Paulina Okunytė Senior Journalist
March 4, 2026 Updated: March 4, 2026 3 min read

How does the malicious campaign work?

ADVERTISEMENT

Credentials were intercepted

How to stay safe?

  • Restricting user consent for new applications
  • Regularly reviewing application permissions
  • Removing unused or overprivileged apps
  • Enforcing Conditional Access policies
  • Deploying cross-domain detection across email, identity, and endpoint systems

ADVERTISEMENT