APT35 (Charming Kitten / Mint Sandstorm) - Malicious OAuth Application Registrat

Detects the creation of Azure AD applications with generic display names, often combined with the addition of delegated permissions for 'Mail.Read' or 'Mail.ReadWrite' scopes. This activity is consistent with OAuth-based consent phishing campaigns used by threat groups such as APT35 (also known as Mint Sandstorm or Charming Kitten) to gain persistent access to user email environments.