#WWAHost
@huntress.com
Sideloaded AppX code abuses WWAHost and WebAuthenticationBroker to steal MFA-backed Microsoft tokens.
-
IOCs: login[.]microsoftonline[.]com, MSAppHost/3[.]0, d590ed36-52b3-4102-aeff-aad2292ab01c
-
#OAuth #ThreatIntel #Windows
OAuth Token Theft via WWAHost
www.huntress.com
September 23, 2026 at 4:07 PM
Sideloaded AppX packages can abuse WWAHost.exe and WindowsRuntimeAccess=all to launch a real Microsoft login flow, capture OAuth codes, and steal tokens even after MFA. Detect via MSAppHost/3.0 traffic. #WWAHost #EntraID #DeveloperMode
OAuth Token Theft Through Microsoft's Front Door | Huntress
A sideloaded AppX package can abuse WWAHost.exe and WindowsRuntimeAccess="all" to open a real Microsoft login flow, capture OAuth authorization codes, and steal access plus refresh tokens even when MFA is completed. The article also shows that the abuse is detectable with a proxy rule for MSAppHost/3.0 traffic to non-Microsoft destinations and highlights Developer Mode as the key prerequisite. #WWAHost #WebAuthenticationBroker #MSAppHost #DeveloperMode #EntraID #MicrosoftOffice
www.hendryadrian.com
September 23, 2026 at 4:15 PM