Back to Intel

Intel Node

Defending SaaS-based applications against ShinyHunters OAuth abuse

lowapt2026-07-13T22:02:41+00:00source excerpt
aptmalwarevulnerabilitytradecraftdetectionwindowscloudemail

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-based applications. The post Defending SaaS-based applications against ShinyHunters OAuth abuse appeared first on Microsoft Security Blog .

In this article Attack chain overview Improving visibility into Salesforce OAuth abuse Mitigation and protection guidance Learn more In a series of campaigns observed between mid-2025 and mid-2026, Microsoft identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing) and supply chain compromise, to target customer SaaS-based applications such as Salesforce instances. The threat actors abused trusted OAuth relationships for unauthorized access, data exfiltration, and persistence.

Two primary intrusion paths were observed including vishing techniques targeting OAuth consent and supply chain compromise through trusted workflows and integrations such as Salesloft and Gainsight.

Read Original Source