AUTO-UPDATED

Defending SaaS-based applications against ShinyHunters OAuth abuse

Microsoft has identified threat actors using ShinyHunters-linked tradecraft to compromise Salesforce customer environments by abusing OAuth trust relationships and social engineering employees through sophisticated voice phishing campaigns.

Key Points

  • Threat actors utilized voice phishing to trick employees into granting malicious OAuth applications access to Salesforce tenants.
  • Supply chain compromises involving trusted integrations like Salesloft and Gainsight allowed attackers to obtain connection secrets and maintain persistent access.
  • Campaigns targeted various industries, including retail, education, and manufacturing, to perform bulk data exfiltration of CRM records.
  • Microsoft upgraded Defender for Cloud Apps to provide near-real-time detection, connected application attribution, and enhanced visibility into OAuth scopes.
  • New posture management tools allow security teams to identify and revoke unused or highly privileged applications to reduce the overall attack surface.

Why it Matters

  • These campaigns demonstrate how attackers can bypass traditional authentication by operating through legitimate, pre-authorized SaaS workflows. Organizations must prioritize the governance of OAuth-connected applications to prevent unauthorized data access and maintain the integrity of their integrated software ecosystems.
Microsoft.com Published by Microsoft Security Research and Microsoft Defender Security Research Team
Read original