Azure App-Mirage: Bypassing Application Impersonation Safeguard
Varonis, Tuesday, October 21st, 2025
Varonis Threat Labs discovered a loophole allowing attackers to impersonate Microsoft applications by creating malicious apps with deceptive names.
Varonis researchers discovered a loophole that made it possible to create malicious applications with deceptive names like "Azure Portal." By bypassing safeguards that prevent the use of reserved names, the vulnerabilities allowed attackers to impersonate Microsoft applications.
When not properly managed, Azure applications can pose serious security risks, such as enabling initial access, persistence, and privilege escalation within a Microsoft 365 tenant. This can result in data loss and reputation damage for organizations.