A new and sophisticated wave of attacks targets organizations by leveraging legitimate Microsoft services. The attacker executes no suspicious files and relies on no classic phishing sites. Instead, it exploits the trust that users and security systems place in Microsoft Power BI, Authentication Broker, and the OAuth Device Code Flow protocol, getting the victim to authorize full access to their corporate account without the attacker ever knowing their password.
Landing Page: The Entry Point
A Business Intelligence platform for data analysis. In this attack scenario, the attacker leverages a legitimate page at app.powerbi.com to redirect the victim and lead them through the process, without any security system raising an alert.
Core of the Attack:
Credential Theft
An authentication protocol designed for browserless devices. The attacker exploits it to generate an access code the victim willingly enters, thereby approving a connection request initiated by the attacker, without realizing it.
The Breach Point: Token Transfer
The authentication service that mediates between applications and the user's account. Once the victim enters the code, Microsoft issues an Access Token directly to the attacker's server, no password required.
The attack unfolds across five consecutive stages, with the victim seeing only familiar, legitimate services at every step.
The attacker breaches a corporate email account and sends an email to the victim's contact list, with a "View Completed Document" button. The email arrives from a known sender, so suspicion levels remain low.
Clicking the link leads to a legitimate page at app.powerbi.com, not a suspicious site. Security systems do not flag the domain, and the user sees a familiar Microsoft service.
The victim is required to pass through a Cloudflare Verification screen, a barrier that prevents automated analysis of the page. They are then shown a page impersonating the DocuSign interface, displaying an access code generated by the attacker's application on Microsoft. Clicking the Open button takes the victim directly to Microsoft's official website to complete the authentication process.
The victim is redirected to the official login.microsoftonline.com and enters the code. From here, two paths exist: if the victim is already signed into Microsoft 365, authentication completes automatically with no password entry required. If not, they are prompted for their username and password. In both cases, everything takes place within an authentic Microsoft interface with an HTTPS padlock, no suspicious signs whatsoever.
Microsoft issues an Access Token and Refresh Token directly to the attacker's server, without needing the user's password.
For a regular user, the attacker gains access to their corporate emails and files.
For an Admin user, the impact can extend to account and permission management across the organization.
Microsoft Power BI, Microsoft Authentication Broker, Cloudflare, DocuSign, and OAuth are entirely legitimate tools. The problem arises from their combination. Many security systems fail to recognize the chain of actions as a threat, since each component on its own is familiar and safe. Because the emails originate from genuine corporate accounts, a single compromised account is enough to turn a trusted vendor into a distributor of the attack to all of their contacts.
There is no visual suspicious sign anywhere in the process. The user sees Microsoft, the browser shows a padlock, and the authentication flow looks real. Yet behind the scenes, the authorization request was created by the attacker and the tokens are sent to them. Recent attacks are most commonly identified when arriving via email, but they can also arrive through browser downloads, chat platforms, and interorganizational file transfer systems.
The attack is designed to bypass each defensive layer individually. The table below shows how each common security system fails against this attack chain, and why a multilayered approach is required.
Since the attack can originate through multiple channels, defense must cover all relevant entry points: email, browser, chat, and file transfer systems. YazamTech offers full coverage of all major channels.
Protection for emails and files received via electronic mail, as part of a multilayered response to attack scenarios that begin in the email channel.
protection for files downloaded through browsers, actively disarming embedded threats before they reach the endpoint.
Detection of suspicious files and links arriving via Teams, WhatsApp, Telegram, and additional communication platforms.
Scanning and filtering of files transferred between organizations via MFT systems, covering an entry point that is often overlooked.