Hunting SharePoint Access Token Theft with Webamon
ID: 35ab4055-bc54-4f35-a929-6cc8a9d2c2a8
STIX ID: report--35ab4055-bc54-4f35-a929-6cc8a9d2c2a8
Threat Score
70/100
Uploaded: 2026-07-28
Published Date: 2026-07-28
Last Modified Date: 2026-08-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
...
...
This Webamon analysis details an active SharePoint/OneDrive-themed phishing campaign that uses disposable domains and Cloudflare-hosted portals to harvest Microsoft 365 access tokens (OAuth), enabling MFA bypass and cloud data exfiltration; it links a persistent Link Fingerprint to multiple malicious domains and Netiface-hosted IPs, provides IOCs and vendor detections, maps the activity to MITRE ATT&CK techniques, and recommends blocking and monitoring the identified infrastructure.
