OAuth Token Theft Through Microsoft's Front Door

Huntress Version 2 imported change current

Imported from official source

A sideloaded package turns a Microsoft-signed binary into an OAuth token theft tool. No phishing domain, no spoofed UI, no browser. Here's how to detect it.

This version

Version
2 of 2
Recorded
October 01, 2026 03:00
Change
Imported change
Content hash
5bad54288890173aca1fad273cacf869
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.