Attackers Target Microsoft Accounts to Weaponize OAuth Apps
After compromising Azure and Outlook user accounts, threat actors use malicious apps with high privileges to conduct crypto-mining, phishing, and password spraying.
Google Oauth Microsoft Exchange Threat Intelligence Outlook Web Application Microsoft Graph Azure Powershell
Source: darkreading.com