OAuth Token Theft Through Microsoft's Front Door
Huntress, Wednesday, September 23rd, 2026
Huntress details an attack that sideloads a Microsoft-signed AppX package to capture OAuth tokens from a legitimate Microsoft sign-in page.
Huntress describes a post-compromise technique in which a sideloaded AppX package abuses Microsoft-signed AppX web hosts to present a genuine Microsoft sign-in page and capture the resulting OAuth tokens, evading signature-based detection since every component is Microsoft-signed.
The attack requires code execution in the user's session plus Developer Mode or an enterprise sideloading policy already enabled, which Huntress calls the real exposure gate to audit and restrict.
Stolen refresh tokens give durable access to a victim's Microsoft 365 data from any machine, with blast radius scaling to the compromised user's privileges. Huntress recommends watching for the MSAppHost/3.0 user agent reaching non-Microsoft destinations.