logo

ConsentFix: A New way to Phish for Tokens

ID: 7cb5c809-55ca-5799-aad6-ffe4a600f0e8

STIX ID: report--7cb5c809-55ca-5799-aad6-ffe4a600f0e8

Feed Name: On the Hunt

Threat Score
65/100

Date Published: 2025-12-17

Date Updated: 2026-04-19

Author: Paul Newton

...
...

This report reproduces and analyses the 'ConsentFix' phishing technique where users are tricked into copying a localhost OAuth redirect URL containing an authorization code; the attacker captures the code, exchanges it for access and refresh tokens (targeting Azure/Azure CLI), and uses those tokens to access Azure resources. The author documents telemetry observed in Entra/SignIn logs (interactive PRT-bound vs non-interactive unbound sessions), highlights Conditional Access/device-correlation shortcomings, and proposes several detection hunts (e.g., token binding flips with IP changes, first-time Azure CLI authentications, and proxy URL matches for localhost redirects).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.