logo

CoPhish: Using Microsoft Copilot Studio as a wrapper for OAuth phishing

ID: 12ebf928-c31b-5ce0-a74a-18744a710bbd

STIX ID: report--12ebf928-c31b-5ce0-a74a-18744a710bbd

Feed Name: Datadog Security Labs

Threat Score
70/100

Date Published: 2025-10-20

Date Updated: 2026-04-27

...
...

Datadog SecurityLabs demonstrates a novel OAuth consent phishing technique that leverages Microsoft Copilot Studio agents: an attacker configures a malicious or externally-registered OAuth application and backdoors the agent's system sign-in topic to forward the victim's User.AccessToken to an attacker-controlled endpoint. The report documents attack scenarios against unprivileged users and Application Administrators (allowing delegated Microsoft Graph access such as Mail.ReadWrite, Mail.Send, Notes.ReadWrite or broader scopes), shows an example token capture, and recommends mitigations and monitoring (stronger application consent policies, restrict app registration, and audit Copilot Studio and Entra ID logs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.