Attackers use a fake browser popup that mimics Microsoft's OAuth login screen to steal credentials from unsuspecting users.