When Apps Attack: Hunting Traitorware and Rogue Microsoft 365 Apps at Scale
Matt Kiely, Christina Parry
BSides NYC 2024 · Day 1 · Tech - Blue
In this compelling talk, "When Apps Attack: Hunting Traitorware and Rogue Microsoft 365 Apps at Scale," Matt Kiely and Christina Parry from Huntress shed light on what they describe as one of the most underappreciated and least understood methods of post-exploitation and initial access in Azure and Microsoft 365 environments: the abuse of OAuth applications. The presentation kicks off with a gripping narrative of Huntress researchers discovering a highly suspicious Microsoft 365 application, named simply with "eight dots" and possessing a credential object named with "five dots," which had delegated access to a specific user's email inbox. This discovery served as the genesis for their extensive research into the prevalence and characteristics of malicious OAuth applications, particularly within the small to medium business (SMB) sector, where such attacks had largely remained theoretical until now.
AI review
Huntress brings real SMB telemetry to an underserved topic — OAuth app abuse is genuinely underexplored in practitioner talks, and the prevalence-based detection methodology is a legitimate contribution. But the talk lands closer to 'solid defensive briefing' than novel research: the attack mechanics are well-documented elsewhere, and the tooling demo feels early-stage.