New CoPhish attack steals OAuth tokens via Copilot Studio agents
ID: 57ae612f-95aa-59e7-8441-6cc9c5c00694
STIX ID: report--57ae612f-95aa-59e7-8441-6cc9c5c00694
Feed Name: Bleeping Computer
Datadog Security Labs describes a novel phishing technique called 'CoPhish' that abuses Microsoft Copilot Studio agents' demo websites and sign-in topics to present legitimate-looking OAuth consent flows hosted on Microsoft domains; attackers can configure redirect and token-exfiltration actions to steal session tokens (including admin tokens) via HTTP callbacks. The report details the attacker setup and flow, highlights the risk that admins can approve malicious app permissions, and notes Microsoft plans product updates while recommending governance, reduced privileges, and consent policy hardening as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
