TA419 Frameless BitB AitM - OAuth2 authorize request to non-Microsoft host
Detects network activity associated with the TA419 threat group's 'Frameless' Browser-in-the-Browser (BitB) Adversary-in-the-Middle (AitM) phishing campaign. The rules identify unauthorized OAuth2 authorization requests to non-Microsoft hosts that match known malicious client IDs, the delivery of BitB overlay scripts, and the subsequent execution of malicious scripts correlated with OneDrive-themed lookalike redirects, indicating a credential theft attempt.
Suricata

