Attackers Target Microsoft Accounts to Weaponize OAuth Apps
After compromising Azure and Outlook user accounts, threat actors use malicious apps with high privileges to conduct crypto-mining, phishing, and password spraying.
Source: darkreading.com