logo

New ConsentFix Technique Tricks Users Into Handing Over OAuth Tokens

ID: 97e00c26-666d-516d-9b2f-54ff1549cafb

STIX ID: report--97e00c26-666d-516d-9b2f-54ff1549cafb

Feed Name: KnowBe4 Blog

Threat Score
60/100

Date Published: 2025-12-30

Date Updated: 2026-04-28

Author: KnowBe4 Team

...
...

Researchers at Push Security uncovered a new OAuth consent phishing technique, dubbed "ConsentFix," that combines ClickFix-style prompts with OAuth authorization code theft: victims are tricked into copying a localhost URL containing an authorization code and pasting it into an attacker-controlled page, which establishes an OAuth connection to an attacker-controlled Azure CLI instance and compromises Microsoft accounts; the attack leverages legitimate first-party tooling and browser context, making it difficult to detect and mitigate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.