logo

New ConsentFix Attack Let Attackers Hijack Microsoft Accounts by Leveraging Azure CLI

ID: ba623367-f352-5467-ac19-872b2ce58013

STIX ID: report--ba623367-f352-5467-ac19-872b2ce58013

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-12

Date Updated: 2026-04-21

Author: Abinaya

...
...

A new "ConsentFix" phishing campaign combines OAuth consent phishing with ClickFix-style prompts to coerce victims into copying a localhost OAuth redirect URL; when pasted into the malicious site this grants attackers access to Microsoft accounts via the Azure CLI, bypassing passwords and phishing-resistant MFA. The campaign uses compromised sites, fake Cloudflare Turnstile checks, conditional email targeting, IP-based evasion and leverages Azure CLI's implicit trust in Entra ID, and defenders are advised to monitor Azure CLI login events and Azure AD logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.