logo

New Attack Technique “ConsentFix” Hijacks OAuth Consent Grants

ID: e197d62d-f06c-56d9-ace3-3f0a1cd785e8

STIX ID: report--e197d62d-f06c-56d9-ace3-3f0a1cd785e8

Feed Name: Arctic Wolf

Threat Score
70/100

Date Published: 2025-12-16

Date Updated: 2026-07-26

Author: Andres Ramos

...
...

**ConsentFix** is a browser-based phishing technique that social-engineers targeted users into copying a legitimate OAuth redirect URL (containing an authorization code) into a phishing page, enabling attackers to exchange the code for cloud access tokens and achieve account takeover without stealing passwords or MFA codes. The report outlines the attack flow, targeted-email gating, and recommended mitigations including never pasting authentication URLs into untrusted sites, deploying endpoint/EDR visibility, and user security awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.