The FBI issued a public service announcement on Tuesday warning that malicious cyber actors have been targeting high-profile individuals, their relatives and acquaintances using a technique called OAuth consent phishing.
OAuth enables websites and web applications to request access to a user’s account on another application without the user exposing their login credentials to the requesting application. The OAuth consent phishing technique sends malicious links to targets under the guise of a file sharing service, an invitation to an event or the need to verify identity. Once permission is obtained, the cyber actor has persistent access to a target’s account. Access only can be revoked by the victim invalidating the token in their application security settings. Changing the password has no effect.
It begins with a phishing email or direct message through a commercial messaging application containing a malicious link. Once victims click on the links, they are redirected to a legitimate communication provider permission request screen. By approving the request, they grant high-level access to a malicious application controlled by the cyber actor who can act on behalf of the user. This includes accessing sensitive data and reading and sending emails without passwords and multi-factor authentication.
The FBI warns of communications from unfamiliar phone numbers and accounts.