{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/oauth-theft/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows (11 24H2 and later)"],"_cs_severities":["high"],"_cs_tags":["oauth-theft","living-off-the-land","windows","sideloading"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eThis threat involves the exploitation of the Windows Web App Host (WWAHost.exe) to facilitate OAuth token theft. By sideloading a maliciously crafted, unsigned AppX package onto a Windows machine with 'Developer Mode' or enterprise sideloading policies enabled, an attacker can manipulate WWAHost.exe to render remote JavaScript that interacts with the WebAuthenticationBroker API. Because the process is a signed Microsoft binary and the authentication dialog is served directly from login.microsoftonline.com, the flow is entirely authentic. The victim completes a legitimate MFA process, providing the attacker with valid access and refresh tokens that bypass typical phishing defenses. This technique is highly effective as it avoids malicious domains, spoofed UIs, and certificate warnings, relying instead on the trust established by Microsoft's own signed binaries.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker ensures the target host has 'Developer Mode' enabled via registry modification (HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\AppModelUnlock) or system settings.\u003c/li\u003e\n\u003cli\u003eAttacker deploys a malicious, unsigned AppX package to the target endpoint using \u003ccode\u003eAdd-AppxPackage -Register\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAppX package is configured with a manifest declaring \u003ccode\u003eWindowsRuntimeAccess=\u0026quot;all\u0026quot;\u003c/code\u003e to gain access to the Windows Runtime API.\u003c/li\u003e\n\u003cli\u003eWWAHost.exe executes the package, rendering remote content provided by the attacker's infrastructure.\u003c/li\u003e\n\u003cli\u003eThe rendered content invokes the \u003ccode\u003eWebAuthenticationBroker\u003c/code\u003e API, passing a legitimate client ID (e.g., for Microsoft Office).\u003c/li\u003e\n\u003cli\u003eWWAHost.exe launches a genuine Microsoft login dialog, authenticating the user against Microsoft servers without browser artifacts.\u003c/li\u003e\n\u003cli\u003eUpon successful MFA, the attacker's listener captures the issued access and refresh tokens for subsequent unauthorized M365 data access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the exfiltration of durable refresh tokens, granting persistent access to the victim's Microsoft 365 environment. The scope of impact scales with the privileges assigned to the compromised user, potentially allowing for business email compromise, data exfiltration, or further lateral movement within the cloud identity environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and restriction of developer settings on endpoint devices.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit the 'Developer Mode' setting across the enterprise fleet and disable it on all workstations where it is not strictly required for development workflows.\u003c/li\u003e\n\u003cli\u003eMonitor for the registration of new, unsigned AppX packages via event logs (e.g., AppxPackaging/Operational logs).\u003c/li\u003e\n\u003cli\u003eImplement network monitoring to detect the 'MSAppHost/3.0' user agent when it initiates connections to non-Microsoft domains or suspicious external infrastructure.\u003c/li\u003e\n\u003cli\u003eConfigure SIEM alerts for the modification of the AppModelUnlock registry key, which is a prerequisite for this attack chain.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-23T14:04:11Z","date_published":"2026-09-23T14:04:11Z","id":"https://feed.craftedsignal.io/briefs/2026-09-oauth-token-theft/","summary":"Attackers can abuse sideloaded AppX packages and the legitimate WWAHost.exe binary to trigger a genuine Microsoft OAuth login flow, capturing valid authentication tokens without traditional phishing indicators.","title":"OAuth Token Theft via Sideloaded AppX and WWAHost.exe","url":"https://feed.craftedsignal.io/briefs/2026-09-oauth-token-theft/"}],"language":"en","title":"CraftedSignal Threat Feed - Oauth-Theft","version":"https://jsonfeed.org/version/1.1"}