TA2552 is a threat actor known for abusing OAuth2 application consent in phishing lures to gain unauthorized Office 365 access.
Analyst brief
TA2552 is a threat actor active since at least January 2020, known for abusing Microsoft Office 365 third-party application consent to gain unauthorized account access. It targets users with well-crafted Spanish language phishing lures that impersonate limited themes and brands, directing victims to a legitimate Microsoft consent page. The actor tricks users into granting read-only permissions to a third-party application via OAuth2, specifically requesting access to resources like contacts and mail. Defenders should focus on strictly controlling third-party application consent in Microsoft 365 environments, monitoring for suspicious OAuth consent requests, and educating users about the risks of granting permissions to unfamiliar applications.
TA2552
unknown
Since January 2020, Proofpoint researchers have tracked an actor abusing Microsoft Office 365 (O365) third-party application (3PA) access, with suspected activity dating back to August 2019. The actor, known as TA2552, uses well-crafted Spanish language lures that leverage a narrow range of themes and brands. The lures entice users to click a link in the message, taking them to the legitimate Microsoft third-party apps consent page. There they are prompted to grant a third-party application read-only user permissions to their O365 account via OAuth2 or other token-based authorization methods. TA2552 seeks access to specific account resources like the user’s contacts and mail. Requesting read-only permissions for such account resources could be used to conduct account reconnaissance, silently steal data, or to intercept password reset messages from other accounts such as those at financial institutions. While organizations with global presence have received messages from this group, they appear to choose recipients who are likely Spanish speakers.