New ConsentFix attack hijacks Microsoft accounts via Azure CLI
ID: 1654ce94-dae8-5053-9bd9-374ec7ca8ab7
STIX ID: report--1654ce94-dae8-5053-9bd9-374ec7ca8ab7
Feed Name: Bleeping Computer
A newly observed phishing campaign dubbed "ConsentFix" abuses the Azure CLI OAuth flow to hijack Microsoft accounts without passwords or MFA. Attackers lure targets to compromised sites that present a fake CAPTCHA and ClickFix-style instructions, prompt the user to complete an Azure CLI OAuth sign-in which redirects with an authorization code, and then instruct victims to paste the redirect URL back into the malicious page so the attacker can exchange the code for access. Push Security and reporting outlets recommend monitoring for unusual Azure CLI login activity and legacy Graph scopes to detect abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
