logo

Hunting SharePoint Access Token Theft with Webamon

ID: 35ab4055-bc54-4f35-a929-6cc8a9d2c2a8

STIX ID: report--35ab4055-bc54-4f35-a929-6cc8a9d2c2a8

Threat Score

70/100

Uploaded: 2026-07-28

Published Date: 2026-07-28

Last Modified Date: 2026-08-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
...
...
This Webamon analysis details an active SharePoint/OneDrive-themed phishing campaign that uses disposable domains and Cloudflare-hosted portals to harvest Microsoft 365 access tokens (OAuth), enabling MFA bypass and cloud data exfiltration; it links a persistent Link Fingerprint to multiple malicious domains and Netiface-hosted IPs, provides IOCs and vendor detections, maps the activity to MITRE ATT&CK techniques, and recommends blocking and monitoring the identified infrastructure.