← Back to feed
PhishingEmerging1 sourceSep 23, 2026 · 13:00via Huntress Blog

OAuth Token Theft Through Microsoft's Front Door | Huntress

Brief

A sideloaded package turns a Microsoft-signed binary into an OAuth token theft tool. No phishing domain, no spoofed UI, no browser. Here's how to detect it.

Read more on Huntress Blog