Malware campaign hijacks Microsoft 365 tenants through malicious OAuth consent apps
Attackers are registering look-alike enterprise applications and phishing global admins into granting Mail.ReadWrite and Directory.ReadWrite.All, sidestepping MFA entirely. We break down the consent-grant chain and the audit-log queries that surface it.