Most Significant ShinyHunters 2026: Malicious OAuth App Impersonating Salesforce Data Loader Requesting Broad API Scopes

Detects OAuth application consent events in Entra ID where the application display name mimics legitimate services like Salesforce or Data Loader while requesting high-risk API scopes (full_access, offline_access, api). This behavior is characteristic of phishing-driven OAuth grant campaigns, such as those observed by the ShinyHunters group.