logo

New CoPhish attack steals OAuth tokens via Copilot Studio agents

ID: 57ae612f-95aa-59e7-8441-6cc9c5c00694

STIX ID: report--57ae612f-95aa-59e7-8441-6cc9c5c00694

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-10-25

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Datadog Security Labs describes a novel phishing technique called 'CoPhish' that abuses Microsoft Copilot Studio agents' demo websites and sign-in topics to present legitimate-looking OAuth consent flows hosted on Microsoft domains; attackers can configure redirect and token-exfiltration actions to steal session tokens (including admin tokens) via HTTP callbacks. The report details the attacker setup and flow, highlights the risk that admins can approve malicious app permissions, and notes Microsoft plans product updates while recommending governance, reduced privileges, and consent policy hardening as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.