Organizations have made considerable progress toward securing standard authentication routes, implementing robust multiparty authentication systems and doing away with static passwords. The result now is that modern cybercriminals are not anymore attempting to steal credentials but are now targeting security protocols through which enterprise applications are operating. The worst consequence of this change is the proliferation of illegal consent grants through hacked OAuth tools.
OAuth is an open-source protocol allowing cloud software like Microsoft 365, Google Workspace, and Salesforce to share data with third-party applications without revealing user passwords. When employees install productivity apps, calendar assistants, or analytical tools, they usually receive a pop-up message asking them for the authority to read their profiles, get access to their calendars, or manage their emails. Cybercriminals use this same convenience to create unnoticed back doors into corporate cloud platforms.
The way a rogue consent grant attack is carried out is through targeted phishing. Instead of guiding the target to a fake login page where they can steal their password, the perpetrator sends a link to the victim asking them to make a legitimate seeming cloud application, which is supposed to be very serious and business-oriented. Since the employee has already signed into their actual corporate account, yet the user doesnβt see prompts asking for their credentials and instead sees a regular consent window generated by the actual trusted identity provider.
After clicking the approval button, the unsuspecting user gives away access to the malicious application. The bad actor now has OAuth token from the cloud provider without having to do anything else: they donβt need the password, nor do they have to bypass the SMS authorization process as the user has given the application the permission to use the cloud system. Even if the company implements password resets or locations-based access rules later on, the application token remains valid.
After gaining authorization, this dangerous application is able to move undetected behind the scenes, using automated API calls. Through this constant access, an attacker can monitor the email communications of the companyβs executives, gather sensitive documents stored in cloud storage, and set up undetectable rules for forwarding emails to other servers. Since this application operates through native API protocols, it is capable of blending in with the background cloud traffic, making it completely invisible to traditional endpoint detection solutions.
To protect from such misuse of permissions, it is crucial to change the approach from defense of the perimeter to proper governance of applications. First, organizations should turn off the default settings allowing regular users to grant permission to use third-party applications without approval from an administrator. The next step is to integrate the system for continuous monitoring of APIs, which is capable of auditing the current permissions and revoking the permissions to any application with a suspicious pattern of data access.
DarkX β DarkX delivers the comprehensive digital risk protection required to secure your cloud ecosystem, continuously tracking malicious app registrations and alerting your security team the moment unauthorized or high-risk OAuth tokens are granted access to your corporate data.
For more research on cybersecurity, privacy, and emerging digital risks, visit:
IntelligenceX - IntelligenceX enables users to discover digital evidence in a privacy-friendly way.
Top comments (0)