New ConsentFix Attack Let Attackers Hijack Microsoft Accounts by Leveraging Azure CLI
ID: ba623367-f352-5467-ac19-872b2ce58013
STIX ID: report--ba623367-f352-5467-ac19-872b2ce58013
Feed Name: cybersecurityNews.com
A new "ConsentFix" phishing campaign combines OAuth consent phishing with ClickFix-style prompts to coerce victims into copying a localhost OAuth redirect URL; when pasted into the malicious site this grants attackers access to Microsoft accounts via the Azure CLI, bypassing passwords and phishing-resistant MFA. The campaign uses compromised sites, fake Cloudflare Turnstile checks, conditional email targeting, IP-based evasion and leverages Azure CLI's implicit trust in Entra ID, and defenders are advised to monitor Azure CLI login events and Azure AD logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
